5 ms·
I already see your comment turning gray for daring to suggest a role for regulation here. Sorry people, if your company releases a negligently insecure IoT devi
by probablybanned 10y ago
I already see your comment turning gray for daring to suggest a role for regulation here. Sorry people, if your company releases a negligently insecure IoT device into the world in any sort of quantity, you are a polluter.
- bsilvereagle 10y agoTo play devil's advocate a bit - if Best Buy sold a Windows 7 laptop that didn't have auto-update turned on by default, and the system gets hacked 3-4 years later from lack of patching, did Best Buy release a negligently insecure IoT device? Did Microsoft release a negligently insecure IoT device by not forcing auto-updates by default? Should users truly own their IoT products and have the ability to turn off auto-updates? This is a very thorny problem.
- probablybanned 10y agoIt depends on the definition of negligence, of course. Sometimes you take all appropriate precautions and still get screwed -- OK. We have a situation where companies are releasing products that every competent professional would recognize as a security trainwreck, and it happens with complete regularity, because the incentives simply do not currently align to make corporate executives give a damn. Due to externalized costs that impact more or less the entire population, this is now a political issue. It's exactly as thorny as environmental regulation, or public safety regulation. Should users truly own their cars and have the ability to disable safety features? I think so, but it shouldn't just be a button on the dash. Should they be able to disable emissions features? I'm not trying to oversimplify here, but I also don't think we should allow the perfect to be the enemy of the good. If there were real incentives to produce secure products, we could expect to see much more investment in secure software, perhaps even verifiable formal methods, and hopefully more industry collaboration/standardization around open source platforms to mitigate risk. It's a tradeoff, but I so often see front-line engineers faced with situations where acting responsibly/ethically with respect to security puts them at odds with management, and that's a clear sign that we're not getting the balance right.
- deleted 10y ago[deleted]
- x0x0 10y agoI'm comfortable with both -- best buy and MSFT liability, and the ability to turn off auto-updates as long as they ship on. The vast majority of people don't change configuration or even have any idea configuration exists. Taking devices with sophisticated configuration and dumping all responsibility off onto end users simply cannot be the way forward for smart devices. Or we'll live in a world where some 12 year old with internet access can download a script that turns your refrigerator off ruining food; turns your kettle/oven/coffeemaker/toaster oven on burning your house down; and makes you an internet porn star by turning cameras on in your home and streaming the video to who-knows-where.