Live data from Hacker News

Schneier: It's Time to Regulate IoT to Improve Cyber-Security

eweek.com

1–10 of 185 posts

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#3
Not that I'm a fan of government regulation for technology issues like this but the security situation is beyond a joke.

For one, it's time to hold companies (and executives!) accountable for security of the data they are charged with protecting, often without your consent (eg Equifax).

For another, insufficient product liability for companies being lax--even negligent--with security. Honestly I don't see an outcome like network-connected lightbulbs bringing down the Internet as particularly far-fetched.

Frankly I don't even know what the market for IoT even is. Who needs $50 light bulbs that will DDoS someone one day? Or, worse, compromise your network to an attacker.

And all for what? So you can turn the lights on after you go through multiple steps to unlock your phone?

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#4
post #2

Yes it is. Importing a cheap Chinese WiFi access point that has an exploitable default password should be as illegal as importing Chinese fentanyl.

That's ridiculous, why? I'd understand some sort of certification process and requiring certified products to have ample warnings but why should it be illegal?

If I want to buy cheap hardware or software that isn't certified I should be able to.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#6
post #4
post #2

Yes it is. Importing a cheap Chinese WiFi access point that has an exploitable default password should be as illegal as importing Chinese fentanyl.

That's ridiculous, why? I'd understand some sort of certification process and requiring certified products to have ample warnings but why should it be illegal? If I want to buy cheap hardware or software that isn't certified I should be able to.

Same reason it's illegal to drive a car that's not certified for roads or build a building that don't meet safety standards.

You have a right to pose a danger to yourself. You don't have a right to pose a danger to others.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#7
post #4
post #2

Yes it is. Importing a cheap Chinese WiFi access point that has an exploitable default password should be as illegal as importing Chinese fentanyl.

That's ridiculous, why? I'd understand some sort of certification process and requiring certified products to have ample warnings but why should it be illegal? If I want to buy cheap hardware or software that isn't certified I should be able to.

> I'd understand some sort of certification process and requiring certified products to have ample warnings but why should it be illegal?

Maybe our current situation is what it might've been like when we had devices that could generate and receive RF emissions but before there was an FCC/global regulatory distribution of spectrum.

If that analogy holds at all, perhaps that might be why it should be illegal to manufacture or import devices which don't conform.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#8
Bullshit.

What makes 'IoT' any different from an ordinary network-connected computer? You're either saying "it's time to regulate networked computing devices" or, "I want to carve out an easygoing regulation-free niche for MY product[s] to artificially excel in."

I try not to be needleslly pessimistic, but this article has no definition of 'IoT' beyond 'networked computer with sensor', so three guesses as to which one it is.

Post reply on HN