Live data from Hacker News

Schneier: It's Time to Regulate IoT to Improve Cyber-Security

eweek.com

11–20 of 185 posts

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#11
post #4
post #2

Yes it is. Importing a cheap Chinese WiFi access point that has an exploitable default password should be as illegal as importing Chinese fentanyl.

That's ridiculous, why? I'd understand some sort of certification process and requiring certified products to have ample warnings but why should it be illegal? If I want to buy cheap hardware or software that isn't certified I should be able to.

The reason a static device connected to the Internet with terrible security should be prohibited is the same reason that devices not meeting FCC certification standards are prohibited.

Both such devices do as much if not more harm to your neighbor as to you. An electrical appliance that interferes with TV broadcasts may not bother you but it bothers your neighbor. An IoT camera that's hacked to DoS a hospital may not bother you but it bothers the patients of the hospital.

In some fictional Libertarian wonderland, these problems could be dealt with neighbors suing neighbors but in the real world we need the state to regulate products with serious cost "externalities".

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#12
post #4
post #2

Yes it is. Importing a cheap Chinese WiFi access point that has an exploitable default password should be as illegal as importing Chinese fentanyl.

That's ridiculous, why? I'd understand some sort of certification process and requiring certified products to have ample warnings but why should it be illegal? If I want to buy cheap hardware or software that isn't certified I should be able to.

I think that EU's approach to this is in its idea the correct one: whoever imports and sells stuff (the legal term is AFAIK "introduces to common market") has to declare that it conforms to relevant safety regulations and is then held responsible should that declaration prove to be wrong. (Slight implementation problem is that the punishment incurred for that is usually too small, typically it boils down to ban of sale of the item involved without any punitive fines)

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#13
On the surface, I agree with this.

In practice I expect it to result in fewer products on the market that are more expensive and no more secure as this sort of regulation will simply select for large companies who are experts at paperwork and soft bribes.

I wish I had a better idea.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#14
post #3

Not that I'm a fan of government regulation for technology issues like this but the security situation is beyond a joke. For one, it's time to hold companies (and executives!) accountable for security of the data they are charged with protecting, often without your consent (eg Equifax). For another, insufficient product liability for companies being lax--even negligent--with security. Honestly I don't see an outcome…

> And all for what? So you can turn the lights on after you go through multiple steps to unlock your phone?

I wanted network-connected lightbulbs so I could have them turn on at the time I needed to wake up, when that time was well before dawn.

I never installed them because I didn't know how to secure them and my schedule got more reasonable, but I think the use case is pretty compelling.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#15
Of course Schneier would want regulation in Iot. That's literally billions of tax dollars that would go to his and other tech consulting and compliance companies. What we really should push for is Open source regulation. Naturally government is always behind on cutting edge tech issues. Open source regulation would improve the efficiency of regulation while saving billions of dollars.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#16
post #6
post #4

Earlier quoted context omitted.

That's ridiculous, why? I'd understand some sort of certification process and requiring certified products to have ample warnings but why should it be illegal? If I want to buy cheap hardware or software that isn't certified I should be able to.

Same reason it's illegal to drive a car that's not certified for roads or build a building that don't meet safety standards. You have a right to pose a danger to yourself. You don't have a right to pose a danger to others.

In my opinion you should be liable for any such danger you pose to others with the ability to shift that liability to whoever sold you source of such danger while assuring you that it is safe.

In fact it is then inconsequential whether some device puts you in direct danger or in danger of somebody comming after you for putting them in danger.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#17

On the surface, I agree with this. In practice I expect it to result in fewer products on the market that are more expensive and no more secure as this sort of regulation will simply select for large companies who are experts at paperwork and soft bribes. I wish I had a better idea.

Agree, regulations could deter entrepreneurs from trying since the barrier to entry could be high. Then again, regulations like HIPAA haven't really stopped a slew of Digital Health shops from trying, so it might not be as bad.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#18

On the surface, I agree with this. In practice I expect it to result in fewer products on the market that are more expensive and no more secure as this sort of regulation will simply select for large companies who are experts at paperwork and soft bribes. I wish I had a better idea.

Utopia, but marketplaces selling only the ones they consider secure would work maybe.

Similar to costco - sometimes they do not sell products that they believe don't have the quality their customers deserve.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#19
I don't think that government certification is the answer here. This will turn security into a check-mark. Companies will do the bare minimum to get certified and won't invest a penny more. This would solve some of the more extreme cases we see, but I doubt it'll make a real impact.

Instead, I feel that accountability would work much better here. If you're selling an IoT device, and you haven't taken industry standard precautions for securing it, then you're on the hook for whatever your device is used for. The same can be applies to companies storing personal information e.g. Equifax.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#20
Even though many people scoff at the idea of government regulations, the economic incentives in IoT security are really all messed up and it's not really clear that the market will fix itself because so much of the damage can be externalized somehow. Does the manufacturer of a cheap and outdated IoT device care if it's participating in some ddos attack? Or like Schneier said, does the consumers care if they don't notice?

There seem to be some soft mechanisms that governments could explore. Maybe something like demanding opening the source code once security updates for the device stop, so consumers could help themselves. Or at least, an even more modest regulation, simply allowing all consumers to hack their own devices without fear of violating any laws.

One thing that could hurt the market is maybe making manufacturers liable for the damages caused by security holes in their devices, but regulation doesn't have to go that far to make an impact.

Post reply on HN