Earlier quoted context omitted.
Oftentimes the dumb, preventable way has repercussions on others. In the case of not updating these IoT devices, it could be a botnet, that really doesn’t even impact the dumb person who failed to take preventive steps. In the case of the lawnmower, expense to the healthcare system.
That's the point. You have a manufacturer that sells a product with N years of support and a customer who buys it and keeps operating it out of support for N+5 years, what is the manufacturer supposed to do about that? Support the product until the end of time? Remote brick the customer's property?
Schneier: It's Time to Regulate IoT to Improve Cyber-Security
181–185 of 185 posts
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#182Earlier quoted context omitted.
That's the point. You have a manufacturer that sells a product with N years of support and a customer who buys it and keeps operating it out of support for N+5 years, what is the manufacturer supposed to do about that? Support the product until the end of time? Remote brick the customer's property?
Apple (at least) has shown us for some time that the device you buy is not really 100% your property. All kinds of proscriptions are in the EULA that prevent you from doing whatever you want with a Mac, and it's far more extensive with iOS devices. So yes, the company is remote bricking their property. What the consumer paid was a one time rental payment, not a purchase.
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#183Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#184Earlier quoted context omitted.
You're right, and perhaps ideally we should have a mix of both accountability and certification. I don't know who could or would sue TiVo for the attack, and I don't know how to solve the problem of out of business companies. This approach has its drawbacks. However, give the certification process some thought too. I can see quite a few drawbacks here as well. First, a significant advantage for established, rich comp…
You’re right, it’s not easy. But even specifying hilariously trivial stuff like HTTPS, certificate pinning, no hardocded backdoors, and per-device random initial passwords would probably be a huge boon. Simple security without even talking about the problems on the service servers. I imagine a market would appear for some of the basic software (Linux diaries, etc) to help make things easy for small companies that do…
I'm surprised PCI (payment card industry) security standards have not been mentioned on this thread. There's a case where non-government regulation has, by some definition, worked.
PCI isn't perfect: if you check all of the boxes, it doesn't mean you're secure, but I'd rather have the industry self-regulate than have politics come into play.
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#185Earlier quoted context omitted.
Apple (at least) has shown us for some time that the device you buy is not really 100% your property. All kinds of proscriptions are in the EULA that prevent you from doing whatever you want with a Mac, and it's far more extensive with iOS devices. So yes, the company is remote bricking their property. What the consumer paid was a one time rental payment, not a purchase.
It sounds a lot like you're proposing enshrining that sort of corporate serfdom in the law and prohibiting the situation where the customer actually owns their own property.