Live data from Hacker News

White House unveils Cyber Trust Mark program for consumer devices

nextgov.com

131–140 of 164 posts

Re: White House unveils Cyber Trust Mark program for consumer devices

#131

Earlier quoted context omitted.

They're not vulnerable in any way that matters. If you manage to get a device in range you can... turn my lights on and off? You can't program them to do malicious things over the Internet. They don't have any sensitive information you can access. There's no damage you can do them. The problem with saying you need auth and crypto is now you just added a bunch of complexity you have to maintain and update and hence no…

Sure, keeping things offline and vulnerable to only local attackers is a valid security posture for some. But the 'I' in IoT is for internet. "Don't build IoT devices" is not a helpful proposal to increase the security of IoT devices, which is the scope of this initiative.

Eh. Debateable. I can control them over the Internet, I am just not delegating Internet access directly to cheap consumer electronics, which simply put, shouldn't be done.

I would argue the crisis of IoT security is caused largely by poor IoT design.

Re: White House unveils Cyber Trust Mark program for consumer devices

#132

Earlier quoted context omitted.

That seems a bit contrived. I would expect my babysitter to be observing a child in-person, not remotely. Regardless, the commonly expected use case for IoT devices is for people to be able to access them from their mobile device, on the internet (thus the 'I' in IoT). IoT devices, as their name implies, are on the internet, and need authentication because of this. The problem is that this use case is real, and peopl…

We use a camera in our daughter's nursery to see whether she's going to fall asleep (if protesting a nap/bed time after laying her down) or whether she's standing in her crib/too wound up. We also use it to keep track of whether she's woken up if we're out in the yard. I do actually have the ability to access it over the Internet through wireguard, but that's something I never need. LAN access suffices. IoT is a mark…

Glad it works for you with your use case. But you have to recognize that you are much more knowledgable than most in this realm. The majority of people expect these smart devices to be accessible from the internet, and do not have the ability or knowledge to configure remote access VPNs.

> You're going to open your garage while you're at the store?

One would mostly likely want to close it then :)

But really, I have an IoT garage door opener so that I can check to make sure it is closed if I forget. This is a common use case. Also, opening it for others when you are away.

> Honestly I don't see the use-case for almost any IoT thing though.

Okay, here's a few: Cameras are useful to see when people are at your house, when packages arrive, etc. Security sensors (or the aforementioned cameras) are also useful to check on the security of your home while you are away and respond if something unordinary happens. People like automatic pet feeders and automatic vacuums to perform tasks while they are away. People like thermostats that can be changed to more economical settings while away, and returned to comfortable settings when (or shortly before) they arrive. AirBnB hosts like being able to change the door code on their properties between visitors, and to monitor and secure their property while not physically there.

If you want some more, just read the reviews of these devices on a site like Amazon, and you'll see what people use them for.

People buy them because they find them useful. That doesn't mean you have to like them or want them. But an initiative to encourage manufacturers to implement basic best-practices is a good idea for other people regardless of whether you personally want them or not.

Re: White House unveils Cyber Trust Mark program for consumer devices

#133
post #124
post #111

Earlier quoted context omitted.

For all things you buy in local shop, responsible owners of shop. If you buy anything abroad, this is your own problem and it is not relevant to subject.

I note that none of these entities are the "customs" that I have heard about.

You just don't know, how work defense of internal market in typical country.

1. Organizations listed in subject (NIST, FCC, deputies from tech companies) constantly create or even invent methods to check products quality and to enforce penalties for offenders, and propose regulations to approve by parliament.

2. Parliament make juridical documents and approve budgets for 1 (and 3,4 when need).

3. Customs limit penetration of abroad subjects to internal market.

4. Police, courts, deal with internal offenders, or with abroad offenders managed to infiltrate through customs to internal market.

In real life, local shop become responsible when sell products from abroad, and regulations limited possibilities to create local shops for foreigners.

Unfortunately, life is constantly changed, technologies constantly grow, so old regulations eventually become obsolete, so all these things work in endless loop.

Re: White House unveils Cyber Trust Mark program for consumer devices

#134

Earlier quoted context omitted.

Sure, keeping things offline and vulnerable to only local attackers is a valid security posture for some. But the 'I' in IoT is for internet. "Don't build IoT devices" is not a helpful proposal to increase the security of IoT devices, which is the scope of this initiative.

Eh. Debateable. I can control them over the Internet, I am just not delegating Internet access directly to cheap consumer electronics, which simply put, shouldn't be done. I would argue the crisis of IoT security is caused largely by poor IoT design.

> I am just not delegating Internet access directly to cheap consumer electronics, which simply put, shouldn't be done.

Yeah, but most people are going to do that. Most people aren't security-conscious professionals, and they do like cheap things.

In a hypothetical reality where home networks were better designed to accommodate remote access, we wouldn't have this problem. And for those of us who can configure networks to be securely accessed remotely, there are definitely better ways to do things.

But that isn't the reality of the landscape of consumer IoT -- which is that people expect to buy a cheap device, connect it to the wifi network of any consumer wifi router, and have it work out of the box. They are already buying these devices regardless of whether they are secure, and will continue to do so. This initiative is about encouraging reasonable incremental changes to the existing reality.

If the requirements for this label were drastic enough that they required people to secure the devices behind behind a firewall, store data locally, and provide remote access only with an inbound VPN or something like that, it would simply be ignored by manufacturers and would have zero impact. Because vanishingly few people are going to replace their Comcast modem/router just to install some IoT device. To most people, they "get wifi" from their ISP. The concept of "reconfiguring a home network" is a nonstarter. Whatever the ISP provides is what normal people use, by default.

Re: White House unveils Cyber Trust Mark program for consumer devices

#135

Earlier quoted context omitted.

They're not vulnerable in any way that matters. If you manage to get a device in range you can... turn my lights on and off? You can't program them to do malicious things over the Internet. They don't have any sensitive information you can access. There's no damage you can do them. The problem with saying you need auth and crypto is now you just added a bunch of complexity you have to maintain and update and hence no…

>If you manage to get a device in range you can... turn my lights on and off? Is that all it's capable of or all you use it for?

So the highest risk device on my RF network is my thermostat. But not only do I get alerts for out of range conditions, the beauty of the local attacker model is most types of attacks become silly: The thermostat has a predefined range of relatively normal temperatures, so the only way to really cause damage is turning it off.

You could bring a custom-programmed RF transceiver and plant it on my property for the job, or you could use a $5 wrench to shut off my natural gas and pull the power shutoff on my AC condenser.

I think the latter is infinitely more likely.

Re: White House unveils Cyber Trust Mark program for consumer devices

#136

Earlier quoted context omitted.

We use a camera in our daughter's nursery to see whether she's going to fall asleep (if protesting a nap/bed time after laying her down) or whether she's standing in her crib/too wound up. We also use it to keep track of whether she's woken up if we're out in the yard. I do actually have the ability to access it over the Internet through wireguard, but that's something I never need. LAN access suffices. IoT is a mark…

Glad it works for you with your use case. But you have to recognize that you are much more knowledgable than most in this realm. The majority of people expect these smart devices to be accessible from the internet, and do not have the ability or knowledge to configure remote access VPNs. > You're going to open your garage while you're at the store? One would mostly likely want to close it then :) But really, I have a…

Don't automatic pet feeders run on timers? And vacuums run on a timer + sensors? And thermostats run on a timer + sensors? I'm not seeing why any of those would be on a network, much less the Internet. In order to put them on a network in the first place, you'd need to have a way to configure it locally (e.g. bluetooth), so why wouldn't you just set schedules there? The whole point of automation is that you set it up once (like when you open it) and then never touch it again. Again, best practice would be to never connect it to a network at all.

The AirBnB use-case seems fair enough. I'll still maintain that having devices connect to hostile C&C servers (which is the current status quo) is not a basic best-practice or an incremental improvement. The recent story about inverters being bricked by a distributor demonstrates why. Literally damaging electrical infrastructure (which is what happened) is one of the the boogeymen used to push for better security, and can put people's lives at risk. That attack should have never been possible.

Re: White House unveils Cyber Trust Mark program for consumer devices

#137

Earlier quoted context omitted.

Eh. Debateable. I can control them over the Internet, I am just not delegating Internet access directly to cheap consumer electronics, which simply put, shouldn't be done. I would argue the crisis of IoT security is caused largely by poor IoT design.

> I am just not delegating Internet access directly to cheap consumer electronics, which simply put, shouldn't be done. Yeah, but most people are going to do that. Most people aren't security-conscious professionals, and they do like cheap things. In a hypothetical reality where home networks were better designed to accommodate remote access, we wouldn't have this problem. And for those of us who can configure networ…

You missed my point. On the contrary, having every light switch in the house need its own network stack is not just insecure, it's overengineered and expensive.

It's fine to have a computer or "gateway" device that calls outbound to a server for outside access, no firewall rules or VPN required. The point is there should only be one point of contact with the outside world, and that's a tech device with enough power to update, secure, etc. As Wi-Fi standards and such change, people should expect to replace it.

Hardware in and on your walls should be dumb, cheap, and long-lasting. Insteon's technology hasn't substantially changed in twenty years, most of my smarthome hardware is over ten years old, and is no less secure or current than when I installed it. And of course, all of it works just like a "dumb" counterpart when the Internet is down or there's no smarthome controller involved. This should be cheaper at scale than "wi-fi smart outlets", if they aren't selling your data to offset the cost.

Re: White House unveils Cyber Trust Mark program for consumer devices

#138

Earlier quoted context omitted.

Glad it works for you with your use case. But you have to recognize that you are much more knowledgable than most in this realm. The majority of people expect these smart devices to be accessible from the internet, and do not have the ability or knowledge to configure remote access VPNs. > You're going to open your garage while you're at the store? One would mostly likely want to close it then :) But really, I have a…

Don't automatic pet feeders run on timers? And vacuums run on a timer + sensors? And thermostats run on a timer + sensors? I'm not seeing why any of those would be on a network, much less the Internet. In order to put them on a network in the first place, you'd need to have a way to configure it locally (e.g. bluetooth), so why wouldn't you just set schedules there? The whole point of automation is that you set it up…

> Don't automatic pet feeders run on timers? And vacuums run on a timer + sensors? And thermostats run on a timer + sensors? I'm not seeing why any of those would be on a network, much less the Internet.

The ones that are on the internet also allow you to trigger them remotely, monitor status, trigger automatically based on geo-location, etc.

Are you trying to say that people could do things another way? Of course they could. But they aren't. They are buying IoT devices, because they like the features.

Personally, I like to set my turn my thermostat off of the eco temperatures before I go home, which is not at the same time every day. I don't think this is a strange use case.

Also, I like to trigger my vacuum remotely when I'm already out of the house. I don't leave the house at the same time every day, so I don't have it set on a timer. I could turn it on before I leave, but I don't really want it trying to roll out the door or bump into me while I'm putting my coat and shoes on.

Again, your critique here seems to be your own person dismissal of these features, which really isn't relevant. Other people buy and use them.

Re: White House unveils Cyber Trust Mark program for consumer devices

#139

Earlier quoted context omitted.

> I am just not delegating Internet access directly to cheap consumer electronics, which simply put, shouldn't be done. Yeah, but most people are going to do that. Most people aren't security-conscious professionals, and they do like cheap things. In a hypothetical reality where home networks were better designed to accommodate remote access, we wouldn't have this problem. And for those of us who can configure networ…

You missed my point. On the contrary, having every light switch in the house need its own network stack is not just insecure, it's overengineered and expensive. It's fine to have a computer or "gateway" device that calls outbound to a server for outside access, no firewall rules or VPN required. The point is there should only be one point of contact with the outside world, and that's a tech device with enough power t…

I understand your point, it's just not relevant. Consumers aren't doing any of that, nor are they going to. Expecting consumers to buy smart-home devices as a whole system and integrate it into their structure is just not practical. The barriers to entry are too high.

I'm glad you bought up Insteon. They're a great example of this, they failed commercially.

https://www.pcmag.com/news/smart-home-company-insteon-shuts-...

I understand the benefits to the architecture you're advocating for. Personally, I started with X10 in 1995. But that simply isn't what people buy anymore. People are buying individual smart-home products, not integrated systems.

The requirements of this program are to address the reality of the types of devices people are actually buying, and the security concerns that affect them.

Re: White House unveils Cyber Trust Mark program for consumer devices

#140

Earlier quoted context omitted.

You missed my point. On the contrary, having every light switch in the house need its own network stack is not just insecure, it's overengineered and expensive. It's fine to have a computer or "gateway" device that calls outbound to a server for outside access, no firewall rules or VPN required. The point is there should only be one point of contact with the outside world, and that's a tech device with enough power t…

I understand your point, it's just not relevant. Consumers aren't doing any of that, nor are they going to. Expecting consumers to buy smart-home devices as a whole system and integrate it into their structure is just not practical. The barriers to entry are too high. I'm glad you bought up Insteon. They're a great example of this, they failed commercially. https://www.pcmag.com/news/smart-home-company-insteon-shuts-…

I mean, fwiw, Insteon is in business today as a new entity. They're producing new hardware and all. It's viable enough a technology to have survived business issues that killed the company.

I disagree with your assumption you understand consumers: Many prefer to buy all products from unified systems, and the complaints about how disconnected and disjointed having odds and ends are have led to Matter, which is struggling to solve the problem.

The major players have all sold home automation hubs, and a lot of solutions still use them, but a lot of the hardware is still overengineered, has a short usable life, and creates security risks.

Post reply on HN