Earlier quoted context omitted.
Make consumers liable. They're really the guilty (by negligence) party anyway, right? Okay, that would be a shock to the system. So grandfather in old devices and/or slowly phase it in. That's still quite a chilling effect though. Well, maybe it should be. Now we're really careful about what we buy. But maybe it's too much. Who wants to expose themselves to a small chance of high liability? Okay, so allow insurance a…
I’m a software developer. I’ve worked for a network security company. I don’t think I’m qualified to try to do that for something I might buy, let alone ‘normal’ people. That’s one of the problems with the market approach. The information assymetry is so big that it’s not a reasonable demand on a person for a $15-20 lightbulb.
Schneier: It's Time to Regulate IoT to Improve Cyber-Security
61–70 of 185 posts
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#62Earlier quoted context omitted.
> opening the source code once security updates for the device stop, so consumers could help themselves That might help the readers of HN, but not users in general. Most users won't bother installing security updates for their PC if it's not forced on them. Updating one's light bulbs with something off github is a non-starter.
It could help the market. It wouldn't be that hard to scan your local network and gather devices and firmware versions (if supported) or fingerprint them if all else fails, and compare against a database of known bad versions and provide weekly or monthly reports by email. I could see this being offered as a selling point of routers. AT&T and Comcast would almost definitely include support in their modem routers just…
Who's going to update the firmware in your light bulbs using a patched open source version of the manufacturer's code?
Edit:
> it's not generally that hard to flash devices that support it, so a report that says "X,Y and Z have exploits, here are some options" could go a long way. Making devices support some minimum standard of local upgradability would help immeasurably.
You're right, it's not hard. But can you imagine regular users doing that? Anti-viruses, Microsoft, Apple, Google and all major browsers had to automate and force updates on users to keep devices secure.
I have a hard time believing that any significant portion of users will flash updated firmware onto IoT devices to fix security vulnerabilities. Heck, when was the last time you checked for firmware updates for your home router? I do this stuff for a living and I don't think I've updated my (current) router's firmware more than once in the last few years.
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#63Always love Mr. Schneier, but I think torts would be a better way of handling this. There are several problems with regulation: a) Whack-a-mole, new ideas and business models arise faster than the speed of government. b) Regulatory capture, like what happened to our banking regulations. c) More often than not, penalties are captured by the regulator, but compensation is not made to the injured parties. d) Internation…
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#64Always love Mr. Schneier, but I think torts would be a better way of handling this. There are several problems with regulation: a) Whack-a-mole, new ideas and business models arise faster than the speed of government. b) Regulatory capture, like what happened to our banking regulations. c) More often than not, penalties are captured by the regulator, but compensation is not made to the injured parties. d) Internation…
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#65Earlier quoted context omitted.
> One thing that could kill the market is maybe making manufacturers liable for the damages caused by security holes in their devices, but regulation doesn't have to go that far to make an impact. What reasonable case is there for making them not liable for the damages caused?
You're right that they should be liable, but pragmatically it's maybe too much of a risk for smaller companies to face some potentially frivolous lawsuit for millions of damages supposedly caused by a ddos originating from some of their devices or something. Surely the right idea in principle, though. I'm just not sure how realistic is it to implement in a smart manner.
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#66Earlier quoted context omitted.
You're right, and perhaps ideally we should have a mix of both accountability and certification. I don't know who could or would sue TiVo for the attack, and I don't know how to solve the problem of out of business companies. This approach has its drawbacks. However, give the certification process some thought too. I can see quite a few drawbacks here as well. First, a significant advantage for established, rich comp…
You’re right, it’s not easy. But even specifying hilariously trivial stuff like HTTPS, certificate pinning, no hardocded backdoors, and per-device random initial passwords would probably be a huge boon. Simple security without even talking about the problems on the service servers. I imagine a market would appear for some of the basic software (Linux diaries, etc) to help make things easy for small companies that do…
That's what I meant by check-mark security. Yes, it is better than nothing, and by all means let's do that. It's low hanging fruit, and it should be plucked. But in the end it amounts to little more than hanging an air re-freshener on a huge pile of garbage.
I'm just pointing out that such certification might cause executives in companies that today put more effort into securing their devices to stop putting in that effort. If it's all the same to the consumer, why spend any more than the bare minimum to get a check mark?
Today there's no clear bar, and a good engineering team will always be able to convince a responsible management that they need to put effort in security. But once that fairly low bar is set, I think that the next order from the management will be "make our devices certifiable and nothing more".
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#67Always love Mr. Schneier, but I think torts would be a better way of handling this. There are several problems with regulation: a) Whack-a-mole, new ideas and business models arise faster than the speed of government. b) Regulatory capture, like what happened to our banking regulations. c) More often than not, penalties are captured by the regulator, but compensation is not made to the injured parties. d) Internation…
The creation and definition of torts (or the generalization of existing torts to cover new relsted domains) is a mechanism of regulation.
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#68The professor‘s response “this is just like all of those internet hit pieces”. Hmmmmm.
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#69Earlier quoted context omitted.
> opening the source code once security updates for the device stop, so consumers could help themselves That might help the readers of HN, but not users in general. Most users won't bother installing security updates for their PC if it's not forced on them. Updating one's light bulbs with something off github is a non-starter.
It could help the market. It wouldn't be that hard to scan your local network and gather devices and firmware versions (if supported) or fingerprint them if all else fails, and compare against a database of known bad versions and provide weekly or monthly reports by email. I could see this being offered as a selling point of routers. AT&T and Comcast would almost definitely include support in their modem routers just…
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#70Yes it is. Importing a cheap Chinese WiFi access point that has an exploitable default password should be as illegal as importing Chinese fentanyl.
As soon as they are successful, they'd be breaking the law.
Just make the owners of IoT devices liable for damage they cause.