Can someone educate me on one IoT point: devices presumably send and receive traffic over a router. That router presumably has security measures such as a firewall in place to reject malicious traffic. So, assuming a competent user, shouldn't security be primarily handled at the router level rather than the IoT device level? Of course IoT devices should also be secured, but my thinking is insecurity and lack of polit…
Schneier: It's Time to Regulate IoT to Improve Cyber-Security
141–150 of 185 posts
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#142Earlier quoted context omitted.
> One thing that could hurt the market is maybe making manufacturers liable for the damages caused by security holes in their devices That's what insurance is for. Something like this was discussed in my torts class in law school, except that was long before IoT devices existed so it was about things like lawn mowers. The idea is that it might make the most sense economically to make the lawn mower manufacturer liabl…
The problem is that this subsidizes stupid people at the expense of not-stupid people. Injuring yourself in dumb, preventable ways should have personal repercussions.
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#143Earlier quoted context omitted.
> One thing that could hurt the market is maybe making manufacturers liable for the damages caused by security holes in their devices That's what insurance is for. Something like this was discussed in my torts class in law school, except that was long before IoT devices existed so it was about things like lawn mowers. The idea is that it might make the most sense economically to make the lawn mower manufacturer liabl…
> That's what insurance is for What are the outcomes for using insurance, and what are the outcomes for using regulation? Does anyone know the answers in a technical policy sense (not in a philosophical sense)? They are different tools useful for different problems. Thinking out loud, insurance seems like a poor solution when people will suffer serious, irreparable harm. If the lawnmower severs a foot, then an insura…
Eh, more or less. Increases in the price of supplies sometimes do lead to an increase in the end price of consumer goods. I agree that this is more likely to happen for inelastic goods, though.
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#144Earlier quoted context omitted.
Doesn't that mean that every single insurance payout will have to involve the courts, taking a long time and not always panning out? If I have an accident I probably need the money on the kind of time-scale that my bills are due on, not the time scale on which courts operate. Even then, that's ignoring the huge overhead introduced.
What court? What payout? Freedom Markets™ are best served by binding arbitration.
My comment about this got 0 attention though...
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#145Even though many people scoff at the idea of government regulations, the economic incentives in IoT security are really all messed up and it's not really clear that the market will fix itself because so much of the damage can be externalized somehow. Does the manufacturer of a cheap and outdated IoT device care if it's participating in some ddos attack? Or like Schneier said, does the consumers care if they don't not…
> One thing that could hurt the market is maybe making manufacturers liable for the damages caused by security holes in their devices That's what insurance is for. Something like this was discussed in my torts class in law school, except that was long before IoT devices existed so it was about things like lawn mowers. The idea is that it might make the most sense economically to make the lawn mower manufacturer liabl…
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#146Even though many people scoff at the idea of government regulations, the economic incentives in IoT security are really all messed up and it's not really clear that the market will fix itself because so much of the damage can be externalized somehow. Does the manufacturer of a cheap and outdated IoT device care if it's participating in some ddos attack? Or like Schneier said, does the consumers care if they don't not…
Copyright law is not in agreement with this. Reasonably, a manufacturer could argue that follow up installments of the software are still actively sold. Then one question is why the fixes wouldn't be ported back to the old release and I guess because differences in the code require significant effort to adapt the fix.
Regulation should seek to equalize ...
> manufacturers liable for the damages caused by security holes in their devices
This is not easy if a chain of bugs in different programs is used to create an exploit. And it would be damaging to warranty wavers especially in open source. After all, the server side will likely run full fledged open source stack. This is where service providers step in. Google would probably like to do monitoring and instrumentation as a service, among others.
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#147So what about the old iPhone 5 and MacBook Pro from 2008 we gave to our kids for music, YouTube and getting started with computers?
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#148On the surface, I agree with this. In practice I expect it to result in fewer products on the market that are more expensive and no more secure as this sort of regulation will simply select for large companies who are experts at paperwork and soft bribes. I wish I had a better idea.
How does regulation work in the aviation industry? The impression I have is that regulation in that space is pretty effective. Without effective regulation I imagine you'd see aircraft falling out of the sky left and right because - and let's be honest here - safety is probably at the bottom of the priorities, both for manufacturers and airline operators. Most people don't believe that accidents can happen to them. P…
Neither argument seems particularly persuasive without being falsifiable.
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#149Even though many people scoff at the idea of government regulations, the economic incentives in IoT security are really all messed up and it's not really clear that the market will fix itself because so much of the damage can be externalized somehow. Does the manufacturer of a cheap and outdated IoT device care if it's participating in some ddos attack? Or like Schneier said, does the consumers care if they don't not…
demanding opening the source code once security updates for the device stop They probably don't even have the (usable) source code.
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#150On the surface, I agree with this. In practice I expect it to result in fewer products on the market that are more expensive and no more secure as this sort of regulation will simply select for large companies who are experts at paperwork and soft bribes. I wish I had a better idea.
> I wish I had a better idea Something that already works are various forms of certification. Examples are: * "Norton protected" on websites * Underwriters Laboratories on US products * US DOD Trusted Computer System Evaluation Critera for how the US military checks the security of a product * ISO 9001 for quality management * Oregon Tilth for certifying organic products Some of these are more valuable than others, b…