4 ms·
What? No. If IoT (and important software in general) doesn't get some aggressive regulation, then people will die at some point. There were already cases where
by igk 9y ago
What? No.
If IoT (and important software in general) doesn't get some aggressive regulation, then people will die at some point. There were already cases where the heating went out in a whole town because of some connectivity issues
...I don't remember the details, but i think it was in Sweden.
Medical devices, industrial machinery, power plants and at some point god forbidden nuclear plants.
I flatly don't care about a startup getting shut down because they had shitty security, there will be another one. The people don't die from that in general. But if a person dies because of lack of regulations, or a strip of land gets contaminated, that is it.
And instead of thinking about corporations being "extorted" for not fixing their shit, how about society having to deal with the fallout of shitty IoT security? DDOS paradise, possibly critical infrastructure being taken over etc
If your business model breaks down if you are forced to do it properly, it was shit. Find a new one. Welcome to capitalism, it's nobodies job to make sure your company succeeds
- sillysaurus3 9y agoYour position is very extreme. Extreme enough that I don't think it's a productive use of time to debate with you. Maybe tone it down a little, take a breath, and realize (a) that people are not in fact dying, and (b) if they do, we can deal with it then. The problem with all of these "People might die!" arguments is that everyone who makes them is always thoroughly convinced that they are right at all costs right now so just fix this!!! that it gets so tiresome. Neither of us has considered all of the possible effects of either action, so we should both carefully examine the consequences of our respective opinions.
- igk 9y agoYou are arguing against something I did not say. I never said we need to do it "at all costs right now so just fix this!!!". I am saying that I value the risk of human lives over the risk of some startups not being created. You didn't specify which part of my positions makes me extreme, so I will just address your a) and b), and your last sentence. b) is what I would call extreme. Yes, people die. But in the discussion "we should protect people" vs "we should't stiffle business", if one of your arguments is "we can deal with it if people dying" is pretty cold (this is me seeing the implied "but we can deal with it worse if startups fail" in this context, so you might want to correct me here) as for a) as far as I can tell, people have not died yet. But we see scenarios on how they could. I'll give examples with real life incidents as inspiration 1. Hacker wants to extort municipality, shuts of heating in winter: http://metropolitan.fi/entry/ddos-attack-halts-heating-in-finland-amidst-winter http://metropolitan.fi/entry/ddos-attack-halts-heating-in-fi... 2. Foreign interest wants to sabotage infrastructure, civilians get caught in collateral damage (also stuxnet) https://www.bloomberg.com/news/articles/2014-12-10/mysterious-08-turkey-pipeline-blast-opened-new-cyberwar https://www.bloomberg.com/news/articles/2014-12-10/mysteriou... 3. Competitor or hacker wants to extort company: https://www.wired.com/wp-content/uploads/2015/01/Lagebericht2014.pdf https://www.wired.com/wp-content/uploads/2015/01/Lagebericht... I would ask you, how many people have to die or how much damage needs to be caused before we but some basic security standards as regulation onto companies? Will one person suffice before I can make that argument? As for this: >Neither of us has considered all of the possible effects of either action, so we should both carefully examine the consequences of our respective opinions. 1. Yes we should, and then we will run out of lifetime because we cannot possibly think of everything. But I'll assume you didn't mean it literally. 2. Considering all relevant consequences I can think of(feel free to add any I forget): If we create a lower bound on security, mandate that all "consumer/industry grade" devices need to live up to that lower limit or face heavy fines, I see the following tings happening: * lots of stuff will not get created, because the margin would be gone. * there will be a new market for security middle ware, or a strengthening of the existing one * there would be a halt in the incrase of power of DDoS attacks * certifying your procuct as consumer or industry grade would need to be an efficient process and would probably add onto the cost of developing a product * GPl and open source software would have to be treated carefully. But if you start in IoT and not touch "classic" software, that can be managed. Probably the distinction between "consumer/industry grade" doesn't make sense for server software and would have to be shifted to the process, i.e. a company can use any software they want in their server AS LONG AS they make use of certain key technologies and industry best practices and have a good process in place. (yes this means no more SaaS without a security team...or a founder willing to learn that shit, or an new company providing that service. You could make an exception for revenue below 50k /year or something if you really want) That are the rough consequences I can see from regulation. Nothing too negative imo On your side, we have the status quo. With dishwashers running linux and having directory traversal vulns https://www.theregister.co.uk/2017/03/26/miele_joins_internetofst_hall_of_shame/ https://www.theregister.co.uk/2017/03/26/miele_joins_interne... companies ROUTINELY storing passwords, possibly without any good crypto and facing no consequences if stuff just stops working https://www.wired.com/2016/04/nests-hub-shutdown-proves-youre-crazy-buy-internet-things/ https://www.wired.com/2016/04/nests-hub-shutdown-proves-your... or if your data gets stolen because of their shitty practices
- sillysaurus3 9y agoOkay, but you are massively underestimating the cost. I feel bad responding to your comment with essentially a one-liner, so even though it's late, here you go: "certifying your product as consumer or industry grade would need to be an efficient process and would probably add onto the cost of developing a product" does not at all capture how thoroughly screwed a new startup will be if they have to devote $60k to a pentest before even getting off the ground. That would have sunk Apple, for example. I don't think most people recognize or appreciate how brittle startups are at the very beginning. You're also assuming that there are two states: "secure" and "not secure." You're further assuming that there is a way to transition from one to the other, by "becoming secure" through some state-mandated process. But it just ain't so. No matter how much money you throw at it, you can only increase security, you cannot prevent security problems. If you've shipped code, you've probably introduced some security problems. We should still try to improve the situation, but it is nearly impossible to make software secure. And in the meantime, it's the perfect tool for competitors to stamp out competition, since only incumbents can afford to be labeled as "secure" (when they're not). I don't think it would significantly curb the power of DDoS attacks, both because DDoS attacks are an inherent problem with the web's design and because hackers are always finding new and innovative ways to increase their DDoS power anyway. Some IoT devices aren't going to make a huge dent in their abilities in that regard. What would help is if pentesting became a regular occurrence due to massive cost reduction. It shouldn't take $60k for a pentest, but it does. The way to achieve this is through open-market competition. Regulation will only raise the price. Regarding your first point, I could take the easy route and say nothing. It's tragic when anyone dies. But it's also a fact of life. Many people will die to self-driving cars, yet there will be many thousands fewer deaths thanks to them. The idea that a single human life is more valuable than raising the standard of living for everybody is as strange to me as it is to you that a single life isn't the most valuable thing. Obviously, my perspective would probably change if someone close to me died due to some fool's bad software. But in that circumstance, the justice system would be as available to me as it is to you, and it was designed for just such an occurrence. It would not offset the heartbreak I'd feel, but at least society has processes in place to do something. this is me seeing the implied "but we can deal with it worse if startups fail" This seems self-evident: Many of the enjoyments we take for granted are thanks to startups. Our quality of life has dramatically improved due to the technology they help usher in. Technological progress is not nearly as inevitable as everyone would like to believe, and it's easy to forget how much better our lives are thanks to it.
- _pmf_ 9y ago> I don't remember the details, but i think it was in Sweden. What about the cases where increased connectivity has prevented blackouts due to increased response time (of which there are probably on the order of 10000 more)?
- igk 9y agoStrong assumption. It's basically selling tiger rocks claiming "but think of all the bad things which DIDN'T happen" without some data that at least hints at the prevention. If you don't have connectivity, you can still prevent blackouts the same or almost the same level. You just need more redundancy in the system, which drives up costs. I actually checked, it was finland and put simplified due to a heating pump continually restarting because it thought there was an error, since its sensors couldn't communicate. If you don't have connectivity, then that heating pump would need a human to regulate it, which leads to higher latency and less efficiency.