5 ms·
I'm not saying that you're right or wrong, but why do you think that?
by Spakman 10y ago
I'm not saying that you're right or wrong, but why do you think that?
- syshum 10y agoHistory. What you will end up with is likely something that is LESS secure but now mandated for anything made/sold legally in the US. The rest of world will be free to do better things You will also end up with mandated Backdoors, weakened encryption, and a variety of other NSA/FBI wish list items that will be included in any "Cyber Security" bill I have no interest in the US congress regulating IoT devices, that will not be good for liberty, or security
- Daishiman 10y agoSo you're saying that things like the Clean Air Act, the EPA, and pollution regulations don't work? Because I look around and it's been working remarkably well.
- nickpsecurity 10y agoHistory under the last mandate was actually a pile of products and research projects that were more secure than anything today. That included Boeing SNS server, BAE XTS-400, Aesec GEMSOS, esp KeyKOS, a secure VMM, an embedded OS in Ada, GUI's immune to keylogging/spoofing, databases immune to external leaks, and so on. All that disappeared in favor of Windows NT and UNIX w/out security the second they eliminated the regulations. There's just enough of a niche market for a few suppliers to be left, esp defense contracts. Most are gone, though, because private markets dont produce strong security if incentives are turning costs into profits.
- syshum 10y agoSo then I guess you also want a Personal Computer or Home Security System to be $1,000,000. Have no Open Source Technology, and generally have no access to the average person let alone low income persons. If Boeing will be the only company allowed to make IoT products then you might as well kill the IoT industry, as each product will cost 100000x more than it should. I classify that BAD... sad you do not Security is one thing, but if it comes at the expense of Open Source and accessible systems then i choose Insecurity. I will choose Freedom over Government every time
- nickpsecurity 10y agoFirst you miss history. Now economics. High-assurance development of the TCB, critical part of system needing it, cost around 35-50% extra on development. Volume sales spread that out. Windows would cost $100-200 with key pieces done that way. The same basically. Only negative effect is rigorous dsvelopment slows release and upgrade cycle. Many firms maximize profit by shipping often then fixing problems later. Market currently rewards that. It's why Lipner, who led high-assurance VMM, favored quick shipping over security in the SDL he built at Microsoft. Now, with regulation, you'd still have the same software being developed. The components would be simpler (JSON subset vs XML). Costs spread out in volume. People would get used to new, huge features taking "two or three quarters" (Lipner) instead of a few weeks. Non-paid or non-critical usage could be done to test out proposals without building whole thing. Far as IoT, solutions already exist that are either inexpensive at OEM level or cheap per unit. Just getting ignored by most of market since there's no regs or liability. Hell, Im typing this on a device running one underneath the OS that cost the same as a ddvice without one. ;)