3 ms·
It's not the failure of the security industry, it's the success of market forces over the security industry. Normal folk want to consume new gadgets because th
by herghost 10y ago
It's not the failure of the security industry, it's the success of market forces over the security industry.
Normal folk want to consume new gadgets because that's the culture we have. So it's a race to put new gadgets with new features in front of people. Sure, as a customer I could insist on my manufacturer having taken security seriously and having their products thoroughly tested and reviewed and hardened and patchable and all that good stuff, but then I'm going to have to pay more money for my gadget than my buddy here who just wants to be able to flush his toilet from his smartphone.
There is literally no consequence for manufacturers of poor quality products where the impact isn't directly impacting their own consumers, and so there's no market force that is going to address this.
When viewed this way, it's a classic case of where we need government/legislature involvement.
- lawpoop 10y ago> Sure, as a customer I could insist on my manufacturer having taken security seriously and having their products thoroughly tested and reviewed and hardened and patchable and all that good stuff How exactly would you insist on that? Ask them? Aren't they going to tell you, "Yes, it's very secure, no worries"?
- lazaroclapp 10y ago> How exactly would you insist on that? How about "show me three different independent security audits by researchers or firms I trust who didn't find major issues in your product"? Sure, there needs to be a sizable group of people demanding that (and be willing to have it be the difference between a $500 and a $5K smart TV), but it is possible. For corporate IoT in certain settings, it might even be plausible.
- tajen 10y agoYou should be on top. Just as we have FCC approvals before you connect a device to 3G, landlines or to the power grid, we'll have to have approvals for all devices connected to the internet. And the top test of the list is a penetration test by a preapproved firm. Note that open-sourcing the firmwares would go great lengths in building a better world: Less spying, more upgradeability, more confidence in the tools, easier pentests and a legacy of new code for future generations.
- rocqua 10y agoYou're going to need either hard regulation, or liability for such breaches to change behaviour. Mostly because, as Mirai shows, the costs are external to the consumer of the broken device.
- pjlegato 10y agoThe major flaw with that proposal is that the government has shown itself to be exceptionally incompetent (just like everyone else) when it comes to security. For example, the NSA's security -- not some underfunded, minor agency, but the NSA itself, the world's leading cybersecurity agency -- has had its security breached on a large scale basis, multiple times. And that is just the beginning of the very long list. It's not unique to the US, either; other governments are the same or even worse in terms of security. Given that government cannot even create working policies to secure systems that it directly controls, even in agencies with practically unlimited budgets and the strongest possible security mandate, how on earth can it be expected to create policy for anyone else, to supervise systems it does not even control, for commercial users with tiny or no budgets? Issuing nice-sounding legal regulations that say 'go forth and be secure' will accomplish nothing.
- rybosome 10y agoFair, but we are not expecting manufacturers to make bullet-proof devices. We are expecting them to make devices that do not let you achieve root access over the internet using an unchanged username and password combination. That's a very easy and specific thing to regulate.
- nradov 10y agoBut they pretty much do have to be bulletproof. Every single device connected to the Internet now effectively has a fully automated machine gun firing at it all the time. One gap in the armor is all it takes.
- pjlegato 10y agoWell, the NSA let a low level contractor (Snowden) walk off with a thumb drive containing half their archive. That's not far removed from not changing the default root password.