Live data from Hacker News

Schneier: It's Time to Regulate IoT to Improve Cyber-Security

eweek.com

171–180 of 185 posts

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#171

Earlier quoted context omitted.

> I wish I had a better idea Something that already works are various forms of certification. Examples are: * "Norton protected" on websites * Underwriters Laboratories on US products * US DOD Trusted Computer System Evaluation Critera for how the US military checks the security of a product * ISO 9001 for quality management * Oregon Tilth for certifying organic products Some of these are more valuable than others, b…

The problem with certifying a device (presumably as secure) is that security is a process, and a device that is secure now may not be tomorrow. For a device to remain secure requires regular updates.

ISO 9001 for example does certify process. I'm sure organic does too.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#172

Earlier quoted context omitted.

> I wish I had a better idea Something that already works are various forms of certification. Examples are: * "Norton protected" on websites * Underwriters Laboratories on US products * US DOD Trusted Computer System Evaluation Critera for how the US military checks the security of a product * ISO 9001 for quality management * Oregon Tilth for certifying organic products Some of these are more valuable than others, b…

Do you think end consumers care at all about certifications?

Consumers certainly can't evaluate each product individually, and that is where certification is a simpler form of evaluation.

It also isn't necessary for every consumer to care about certification. All it takes is a minority to do so - enough to tip sales away from the competition. Certification is also easy to mention in reviews and product feature lists.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#173
post #149
post #43

Earlier quoted context omitted.

demanding opening the source code once security updates for the device stop They probably don't even have the (usable) source code.

Maybe we should mandate that a reasonable source code is deposited somewhere?

And you'd only discover that the code doesn't even build until it's too late.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#174
Wouldn't it make more sense to regulate all devices that autonomously communicate with 3rd parties such as the manufacturer?

That way the regulation would also apply to self-updating smartphones, operating systems, smart TV's...

I just don't see how IoT is fundamentally more of a risk than Internet-connected devices with camera's, microphone's, light, movement and rotation sensors and GPS... while also having access to all your personal data.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#175

Earlier quoted context omitted.

What court? What payout? Freedom Markets™ are best served by binding arbitration.

You obviously hit a nerve with this one. I agree with you though, binding arbitration is a major issue. For example, there was recently a thread on dell shipping Ubuntu. The Dell image of Ubuntu has a EULA that includes, you guessed it, binding arbitration. My comment about this got 0 attention though...

Your post might've got killed by corporate hasbara, did you check that it isn't dead? I'm half serious.

EULA's should die already. I think the problem is that they require of non-experts to parse legal documents. Very, very few people who agree to EULA's have decent grasp of the implications, even if they work their way through the whole text.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#176
post #170

Earlier quoted context omitted.

OK, so how do you distinguish automatically "abuse" from "proper use" for arbitrary devices, and how would putting the code that is able to do that on a separate device be easier than compiling it into the firmware of the devices themselves?

Look, your PC and BYODs are still prone to attacks, they're much much more powerful than those networked IoT devices, and they still need firewall to protect. I of course hope all firmware will be safe, and they should be safe as much as possible, still, you need a more powerful device to safeguard them. Put another way, no matter how secure my wifi-bulb is designed, I'm not going to expose it to the internet, and I…

> they still need firewall to protect

Why?

> you need a more powerful device to safeguard them

Why?

> I'm not going to expose it to the internet, and I will put it behind my firewall/NAT-router.

Why?

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#177
I would rather see independent (private) solutions before inviting a bunch of bureaucratic red tape to manufacturers.

For example, someone could create a company that issued certificates of security. Manufacturers would pay a small fee to these companies to perform security tests and give them a certificate of security. They can put that label on their products to provide confidence to consumers. Some products may warrant a much higher level of scrutiny than others so there could be different levels or different companies that offer it.

I think people will naturally choose the products that are 'certified' over the ones that aren't, and manufacturers will have to end up doing it to stay competitive.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#178

Earlier quoted context omitted.

Why would light bulbs need to be connected to the Internet for the use case of being turned on at a specific time? They'd just need to be connected to a timer for this. I mean, an Internet connected light bulb use-case would a bulb that flashed whenever a stock you owned went down in price, which is ridiculous despite being the least ridiculous example I could think of. IoT security cameras and an automated kitchen y…

Exactly. Nearly everyone who tries to explain why I would want Xyz device to connect to the Internet cites a use case that... doesn't require an Internet connection! Turning lights on and off at certain times, buzzing when a doorbell is pressed, thermostats and sprinklers that respond to the weather. Even security cameras don't need an Internet connection when being viewed locally, yet my Dropcam insists on sending a…

Indeed,

You get a combination of a wifi network being the one sort network every person is guaranteed to be already on and every company dreaming of cloud-based-app supremacy "synergizing" every useless whatsit they have access and the IoT nightmare is in full swing.

"What could possibly go" - wait, we've seen answers to that one already.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#179
post #162

Earlier quoted context omitted.

> That's what insurance is for What are the outcomes for using insurance, and what are the outcomes for using regulation? Does anyone know the answers in a technical policy sense (not in a philosophical sense)? They are different tools useful for different problems. Thinking out loud, insurance seems like a poor solution when people will suffer serious, irreparable harm. If the lawnmower severs a foot, then an insura…

On insurance vs regulation - What isn't being mentioned here is that insurers will require insured companies to do a bunch of stuff in order to remain insured. Have some processes in place, do some things, and so on. Just like your car insuruance isn't valid if you drink and drive, your software company insurance might not be valid if you aren't using source control and have no testing or code review proccess. So in…

Excellent points; thanks.

I'd only add that the insurer's incentive to reduce risks to their profits is not always aligned with consumer's risks. As a simple example, the insurer may require the vendor to have consumers sign away their legal rights to reduce the risk of expensive lawsuits.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#180

I would rather see independent (private) solutions before inviting a bunch of bureaucratic red tape to manufacturers. For example, someone could create a company that issued certificates of security. Manufacturers would pay a small fee to these companies to perform security tests and give them a certificate of security. They can put that label on their products to provide confidence to consumers. Some products may wa…

Lightning cables that aren't MFi certified are still widely used. See their presence is gas stations and other stores nationwide. Lots of "MFi certified" cables online are likely fake. Who knows?

USB Type-C can deliver enough power to seriously damage your $1000 MacBook if the cable/adapter is designed poorly. There is a certification process, but most products on the market are still below-par. Below I will link a list. Guess what, those "bad" products are still bought en masse.

This week, I discovered that pretty much all the water filters that are popular for the type I'm looking for aren't even certified to filter out harmful materials. NSF 53 certification exists, but it looks like the market didn't do any research into it and trusted NSF 42, which was touted but is a much less strict standard, filtering out odor and taste (important in its own way). Theoretically, these filters could be passing on lead and asbestos.

Your solution _might_ work for a _part_ of the market, but it is almost guaranteed that there will still exist a significant (if not majority) part of the market, that doesn't care about certification/prefers the cheaper product.

https://docs.google.com/spreadsheets/d/1vnpEXfo2HCGADdd9G2x9...

Post reply on HN