Some of the comments here seem to argue that creating legislation that demands basic security baselines will not get the job done. In fact in a recent interview[1] Jen Easterly (head of CISA gov) fell into the same trap (assuming because she didn't want to upset tech company lobby groups) so her message was reduced to shouting into the void (asking vendors "please be-good"):
> Addressing these issues requires a long-term approach and not simply a new set of regulations or industry standards. Easterly said it will require the leaders of technology companies to focus explicitly on building safer products, provide transparency into their development and manufacturing processes, and an understanding that the burden of safety should not fall solely (or even mainly) on customers.
I'm right now struggling to get a bunch of US IoT companies to agree on a very basic set of security standards that would allow more interoperability. All we're asking are basic best practice to anyone working in security (e.g. ETSI 303 645). And the reason why I'm struggling is because in the EU these baselines are becoming the law as of 1st Aug. 2024 with the Radio Equipment Directive (RED). And in addition these same kind of guardrails will also become law with the Cybersec Resilience Act in 2025 expanded to the cloud and mobile apps. So this thing is coming and the US which has a lot better standards (thanks to NIST but lacks legalization due to power of lobby groups) looks like a total laggard here to a point where it becomes embarrassing.
Nobody in their right minds would argue there are unreasonable provisions in these proposals for RED (or the CRA). Yet all the US based vendors who do not sell into EU markets shout "bloody murder".
And it's hilarious how they're all grandstanding about "how dare the communist EU is telling business how to innovate".
Legislation works. Begging vendors to come up with better controls by themselves will not.
Anyone who has spent even a single day working in security in a company where security isn't part of their core value proposition (or isn't _the_ product) will know the only way to enforce even the most basic security and safety controls[2] is by legislation.
You want a unified charging standard for EV? Make it the law!
You want a single type of charger for all phones? Make it the law.
You want your coding standards to meet guidelines for functional safety? Make them law.
You want to eliminate OWASP Top-10 from production code? Make it the law.
[1] https://duo.com/decipher/strong-security-has-to-be-a-standar...
[2] entirely related: The Humble History of the Crash Test Dummy https://www.motorbiscuit.com/the-humble-history-of-the-crash...