Live data from Hacker News

What If We Put Warnings on IoT Devices?

troyhunt.com

81–90 of 159 posts

Re: What If We Put Warnings on IoT Devices?

#81

In California, there is a law that basically everywhere (e.g. all apartment complexes) must have a sign that specifies that the compounds used on site can cause cancer or birth defects or whatever. But because the signs are pervasive, they are basically useless. This feels kind of like that.

The problem I've always found with the California warnings is that they're so damn generic. There's nothing forcing companies to tell you what compound is harmful, where it is, or what it's used for.. A fishing sinker made from lead is pretty obvious when you see that warning. There's only one ingredient, lead, and it's obvious why it's harmful. But when you buy a complex product that says "this product contains chem…

Some warnings speak of "specific birth defects" which is something greater than a may/might do something. Normally this is reserved for the class of chemicals and drugs that post-thalidomide are known to cause limb-reduction defects.

Re: What If We Put Warnings on IoT Devices?

#82

In California, there is a law that basically everywhere (e.g. all apartment complexes) must have a sign that specifies that the compounds used on site can cause cancer or birth defects or whatever. But because the signs are pervasive, they are basically useless. This feels kind of like that.

The problem I've always found with the California warnings is that they're so damn generic. There's nothing forcing companies to tell you what compound is harmful, where it is, or what it's used for.. A fishing sinker made from lead is pretty obvious when you see that warning. There's only one ingredient, lead, and it's obvious why it's harmful. But when you buy a complex product that says "this product contains chem…

>There's nothing forcing companies to tell you what compound is harmful, where it is.

This is changing. But you still have the problem of over reporting. There are provisions to verify that your use of the material is safe, but it's so much easier, and so much less risky, to just slap the label on.

Re: What If We Put Warnings on IoT Devices?

#83

Earlier quoted context omitted.

Ya, but what products? I'm sure California understood that it would be difficult for property managers to do a complete audit, so allowed this warning as a cop out (it might be that they have none of those chemicals, but who knows, we will put up the warning just in case).

It always trickles down. The property managers know who built the buildings. The construction company knows what companies produced the construction materials. The company that made the construction materials knows what chemicals are in them. That's the person who writes the warning, and the construction crew tells the property manager, and the property manager keeps a list in their office for public viewing.

I think it has more to do with the gardeners and maintnence than the orig construction. But ya, they so much as use a floor cleaner from the grocery store, that would have to be documented.

Re: What If We Put Warnings on IoT Devices?

#84
If we follow Troy's line of reasoning, then we would need to add these warnings to phones, tv's, websites, credit cards -- just about anything that contains data about you.

I guess the main point the author is trying to make is that data can get compromised, and some people might not be aware of that.

Nothing new or groundbreaking.

Re: What If We Put Warnings on IoT Devices?

#85

Earlier quoted context omitted.

Even if they did, would it matter? It would be some chemical term, like the one you see in an ingedient list, that is meaningless to most people. And these are places, not products...with gardens. Even if they use organic pesticides, they probably still have to put up the warning.

> that is meaningless to most people. Therefore no people should be allowed to know? For what it's worth, I'm not in favour of California's labelling requirements either. But just because something is meaningless to the majority of the population doesn't mean it's meaningless to the entire population. And it is specifically the population that is interested in knowing it that finds it least meaningless!

If it is meaningful to only a small portion of the population then that portion should pay for obtaining this information and not force the rest to pay. If you add legal costs these warning like most of regulations are really expensive.

Re: What If We Put Warnings on IoT Devices?

#86
post #27

Simple rule: I buy it, I own it and it should not need an external service to operate. If it does then I'm not buying it. None of those grafted on services for me, I really have yet to see anything that was so compelling that I would give up and consent to essentially renting a device and having an account with some service to make it useful. That way you also don't need to warn anybody about the lousy security, I'm…

> Simple rule: I buy it, I own it and it should not need an external service to operate. If it does then I'm not buying it. That's a good rule, but good luck opting out once most manufacturers no longer give you an option.

> That's a good rule, but good luck opting out once most manufacturers no longer give you an option.

The irony is that this is Hacker News and so many people building those things hang out here. If we want to make a difference, we have to start making a difference.

Re: What If We Put Warnings on IoT Devices?

#87
post #58

Urm, you know, people got used to IoS. Telling other people how to make their choices is telling other people what to do. It's not always nice, and frankly, never actually works.

> It's not always nice, and frankly, never actually works.

It works and is profitable. Just ask any advertiser. And it is nice. It increases corporate profits. What could be nicer than that? /s

Re: What If We Put Warnings on IoT Devices?

#89

Simple rule: I buy it, I own it and it should not need an external service to operate. If it does then I'm not buying it. None of those grafted on services for me, I really have yet to see anything that was so compelling that I would give up and consent to essentially renting a device and having an account with some service to make it useful. That way you also don't need to warn anybody about the lousy security, I'm…

> Simple rule: I buy it, I own it and it should not need an external service to operate. If it does then I'm not buying it.

While this sounds like a wonderful idea (and one I would subscribe to), it doesn't address the fundamental problem with IoT security.

Most operating systems have updates made available on a monthly, weekly, or even daily basis, in order to keep them secure. Mostly, we know how to do this, the operating system generally auto-updates, and the people producing the OS keep up to date. This is necessary because the time from discovery of a bug to exploitation of a bug can be very short.

IoT devices rarely have this. A Meile washing machine should last 20 years, but there is no way I'm leaving a computer with a 20-year old OS on the internet. That's just asking for trouble. There's also the point that OS makers generally have a clue about computing security, but IoT makers generally do not.

A computer with no way of updating the OS for security (i.e. an IoT device) has a usable lifespan of maybe a couple of months. If you're lucky.

Post reply on HN