Live data from Hacker News

What If We Put Warnings on IoT Devices?

troyhunt.com

141–150 of 159 posts

Re: What If We Put Warnings on IoT Devices?

#141

Simple rule: I buy it, I own it and it should not need an external service to operate. If it does then I'm not buying it. None of those grafted on services for me, I really have yet to see anything that was so compelling that I would give up and consent to essentially renting a device and having an account with some service to make it useful. That way you also don't need to warn anybody about the lousy security, I'm…

> Simple rule: I buy it, I own it and it should not need an external service to operate. If it does then I'm not buying it. While this sounds like a wonderful idea (and one I would subscribe to), it doesn't address the fundamental problem with IoT security. Most operating systems have updates made available on a monthly, weekly, or even daily basis, in order to keep them secure. Mostly, we know how to do this, the op…

This is all good stuff, but actually raises another important question for our new wave of technologies: how do/should we regulate products where some form of after-sale updates is necessary to maintain proper function?

For example, in my country, it is typically the merchant who sells you a physical product who will be on the hook under consumer protection legislation if the product fails to meet acceptable standards somehow. It's implicit that they would in turn try to recover any losses from their own suppliers later, but that's not the end customer's problem, and the merchant is the one who loses out if they don't have such a recovery mechanism available.

However, that's hardly fair if there's a third party involved (the developer of some software component within the product) who can update it in whatever good or bad ways they want without any knowledge or consent on the part of the merchant. It is particularly unfair if that third party is also a relatively large or even monopoly supplier and can dictate more-or-less arbitrary terms to merchants selling their products, who typically do not benefit from a baseline of legal protections against exploitation in the same way that end customers do.

In short, our entire framework of consumer protection and product liability laws has been built around the model of a linear supply chain resulting in a single point and time of sale, but that model simply doesn't apply any more in many cases.

Re: What If We Put Warnings on IoT Devices?

#142
post #78

Simple rule: I buy it, I own it and it should not need an external service to operate. If it does then I'm not buying it. None of those grafted on services for me, I really have yet to see anything that was so compelling that I would give up and consent to essentially renting a device and having an account with some service to make it useful. That way you also don't need to warn anybody about the lousy security, I'm…

Also sums up my philosophy, at least ideally. (I dread the next time I have to buy a car...)

(I dread the next time I have to buy a car...)

I agree.

Personally, I actively do not want OTA updates, or much of any remote communication to or from my car at all, that isn't 100% isolated from all the essential vehicle control, safety and security systems.

I can tolerate the idea of a vehicle-initiated automatic emergency call system, or a remotely activated but otherwise independent tracker device as an anti-theft measure. These have a clear and beneficial purpose for me as the owner/driver, and if strictly limited to that stated purpose they pose minimal privacy, security or safety concerns.

Anything beyond that, I would rather do without. And I'll maintain my current car indefinitely rather than buying any of the current generation of might-work-or-might-kill-you stuff. The lack of effective regulation and oversight in the auto industry was scary when it was just mechanics, it became more scary when software started to eat the industry, and it's just plain terrifying in the new, connected era.

Re: What If We Put Warnings on IoT Devices?

#143
post #67
post #34

Earlier quoted context omitted.

Yes. There's this doorbell (400-1500 USD) that connects via internet to a central host, and then notifies you on your smartphone. Seems sort of a neat idea, but a house lasts several decades - is that startup and its server going to be around that long? http://www.doorbird.com

Well, not many things remain the same in a house over several decades. Yes, such a doorbell is more or less an expensive toy that likely will cease to work within half a decade, but normal doorbells tend to break once a decade as well.

And I just visited a building that is several centuries old, and gained admission by using a solid iron knocker on a big wooden door, both of which are original.

Not all technological changes are advances.

Re: What If We Put Warnings on IoT Devices?

#144
post #27

Earlier quoted context omitted.

> Simple rule: I buy it, I own it and it should not need an external service to operate. If it does then I'm not buying it. That's a good rule, but good luck opting out once most manufacturers no longer give you an option.

Surely the idea of overt, explicit labelling about the risks of using these devices is to create the possibility of competing brands using their better security/privacy as an advantage, and thus promote more secure and private products? I've long advocated the basic idea from the article here, but in a much more blunt way, with explicit warnings about the potential consequences: Identity theft is the fastest rising c…

>Surely the idea of overt, explicit labeling about the risks of using these devices is to create the possibility of competing brands using their better security/privacy as an advantage, and thus promote more secure and private products?

Which is more likely, that companies will actually create more secure devices, or that companies will simply label their insecure devices as required knowing full well that most consumers will ignore the labels? How many people read the TOS for anything they sign up for? How many Hacker News users, who should know better, read the TOS of anything they sign up for? Do people stop smoking because we put cancer warnings on cigarettes? Some, maybe, but enough for cigarette makers to make their products healthier?

It seems to me that the most likely result of labelling IoT devices would be to consumers and businesses to accept that lack of safety as an acceptable tradeoff for whatever features the device offers.

Re: What If We Put Warnings on IoT Devices?

#145
post #144

Earlier quoted context omitted.

Surely the idea of overt, explicit labelling about the risks of using these devices is to create the possibility of competing brands using their better security/privacy as an advantage, and thus promote more secure and private products? I've long advocated the basic idea from the article here, but in a much more blunt way, with explicit warnings about the potential consequences: Identity theft is the fastest rising c…

>Surely the idea of overt, explicit labeling about the risks of using these devices is to create the possibility of competing brands using their better security/privacy as an advantage, and thus promote more secure and private products? Which is more likely, that companies will actually create more secure devices, or that companies will simply label their insecure devices as required knowing full well that most consu…

Do people stop smoking because we put cancer warnings on cigarettes?

It's hard to separate effects, but certainly here in the UK where we now have aggressive labelling restrictions on packets and visible displays in shops and strict limits on smoking in most public places, smoking seems to be much less of a problem than it used to be. In particular, culturally among younger generations, social smoking is no longer the norm in the way that perhaps it was for their parents or grandparents.

I see no reason that similarly explicit labelling requirements for dangerous IoT devices couldn't help, particularly if also combined with restrictions on use in contexts that could affect others.

Failing that, I personally have no problem with powerful regulations that pose an existential threat to businesses that are deliberately and flagrantly cavalier with security or privacy in the online era (and I write that as someone who is typically very cautious about regulatory over-reach and unintended consequences).

Re: What If We Put Warnings on IoT Devices?

#146
post #144

Earlier quoted context omitted.

>Surely the idea of overt, explicit labeling about the risks of using these devices is to create the possibility of competing brands using their better security/privacy as an advantage, and thus promote more secure and private products? Which is more likely, that companies will actually create more secure devices, or that companies will simply label their insecure devices as required knowing full well that most consu…

Do people stop smoking because we put cancer warnings on cigarettes? It's hard to separate effects, but certainly here in the UK where we now have aggressive labelling restrictions on packets and visible displays in shops and strict limits on smoking in most public places, smoking seems to be much less of a problem than it used to be. In particular, culturally among younger generations, social smoking is no longer th…

>I personally have no problem with powerful regulations that pose an existential threat to businesses that are deliberately and flagrantly cavalier with security or privacy in the online era (and I write that as someone who is typically very cautious about regulatory over-reach and unintended consequences).

To me, that combined with a campaign of education and raising consumer awareness might be more effective.

Re: What If We Put Warnings on IoT Devices?

#147

A little ironic: I tried to share this article on the #offbeat Slack channel at my work, but the automatic preview image Slack generated for it (from the top cover image of the article, which you can't really see most of, unless you view the image separately) is a (pretty NSFW) fake front-of-the-box for a "We-Vibe" IoT vibrator: "We can see how kinky you are". Not what I was planning to share with my coworkers. I'd r…

I sort of wish Slack had a way to disable the preview image feature; I've run into this several times where a reasonable, work-safe article was processed into a picture not-so-suitable for Slack. It mostly seems to be cases like this one, where the first image is concealed or contextualized in the article but treated like a normal header image by Slack. I think one that got me worst was a piece responding to someone…

An X shows up next to the preview/unfold when hovering, and allows you to delete the preview, at least in the full desktop app.

Re: What If We Put Warnings on IoT Devices?

#148
post #146

Earlier quoted context omitted.

Do people stop smoking because we put cancer warnings on cigarettes? It's hard to separate effects, but certainly here in the UK where we now have aggressive labelling restrictions on packets and visible displays in shops and strict limits on smoking in most public places, smoking seems to be much less of a problem than it used to be. In particular, culturally among younger generations, social smoking is no longer th…

>I personally have no problem with powerful regulations that pose an existential threat to businesses that are deliberately and flagrantly cavalier with security or privacy in the online era (and I write that as someone who is typically very cautious about regulatory over-reach and unintended consequences). To me, that combined with a campaign of education and raising consumer awareness might be more effective.

Such a campaign would be helpful, I agree.

Re: What If We Put Warnings on IoT Devices?

#149
post #24

Earlier quoted context omitted.

Edit: I might be wrong and I have to go before I can get sources on it.

They also miss a lot of things that do contain or emit chemicals that cause cancer, like dryer sheets.

Found my citation for that: http://www.drsteinemann.com/Articles/Steinemann%20et%20al.%2...

Re: What If We Put Warnings on IoT Devices?

#150

Earlier quoted context omitted.

Or how much of it there is. Parts per million/billion? I'm pretty interested in how much cadmium and mercury gets into my system because they're bad news for the brain. At the same time, mercury is also in air so it's kind of inescapable. Parts per billion is interesting information because then I can control how much I ingest the way I do for food that is fattening.

It would be much more useful if it were in the form of "This property contains substances determined by the state of California to be toxic to humans. The site report may be viewed in person at 123 Maple St, Suite 200, San Mateo, or electronically at https: //sitereport.ca.us/ " Then the print report would basically be a binder full of MSDS-like information sheets, along with the history of measurements recorded on t…

That supposes testing of that nature is actually done for every item/location that has one of those warnings. It is not. Testing is expensive. The costs if you lose a lawsuit due to not displaying the warning when you should have, even more so. People are pretty desensitized to seeing the warnings. So the logical decision made by many business owners is to display the warning even if no tests have been conducted showing the presence of the chemicals and sometimes even if there is no reason to believe there are any harmful chemicals at all. There's no penalty for displaying a superfluous warning.
Post reply on HN