5 ms·
You are arguing against something I did not say. I never said we need to do it "at all costs right now so just fix this!!!". I am saying that I value the risk o
by igk 9y ago
You are arguing against something I did not say. I never said we need to do it "at all costs right now so just fix this!!!". I am saying that I value the risk of human lives over the risk of some startups not being created.
You didn't specify which part of my positions makes me extreme, so I will just address your a) and b), and your last sentence.
b) is what I would call extreme. Yes, people die. But in the discussion "we should protect people" vs "we should't stiffle business", if one of your arguments is "we can deal with it if people dying" is pretty cold (this is me seeing the implied "but we can deal with it worse if startups fail" in this context, so you might want to correct me here)
as for a) as far as I can tell, people have not died yet. But we see scenarios on how they could. I'll give examples with real life incidents as inspiration
1. Hacker wants to extort municipality, shuts of heating in winter: http://metropolitan.fi/entry/ddos-attack-halts-heating-in-finland-amidst-winter http://metropolitan.fi/entry/ddos-attack-halts-heating-in-fi...
2. Foreign interest wants to sabotage infrastructure, civilians get caught in collateral damage (also stuxnet)
https://www.bloomberg.com/news/articles/2014-12-10/mysterious-08-turkey-pipeline-blast-opened-new-cyberwar https://www.bloomberg.com/news/articles/2014-12-10/mysteriou...
3. Competitor or hacker wants to extort company:
https://www.wired.com/wp-content/uploads/2015/01/Lagebericht2014.pdf https://www.wired.com/wp-content/uploads/2015/01/Lagebericht...
I would ask you, how many people have to die or how much damage needs to be caused before we but some basic security standards as regulation onto companies? Will one person suffice before I can make that argument?
As for this:
>Neither of us has considered all of the possible effects of either action, so we should both carefully examine the consequences of our respective opinions.
1. Yes we should, and then we will run out of lifetime because we cannot possibly think of everything. But I'll assume you didn't mean it literally.
2. Considering all relevant consequences I can think of(feel free to add any I forget):
If we create a lower bound on security, mandate that all "consumer/industry grade" devices need to live up to that lower limit or face heavy fines, I see the following tings happening:
* lots of stuff will not get created, because the margin would be gone.
* there will be a new market for security middle ware, or a strengthening of the existing one
* there would be a halt in the incrase of power of DDoS attacks
* certifying your procuct as consumer or industry grade would need to be an efficient process and would probably add onto the cost of developing a product
* GPl and open source software would have to be treated carefully. But if you start in IoT and not touch "classic" software, that can be managed. Probably the distinction between "consumer/industry grade" doesn't make sense for server software and would have to be shifted to the process, i.e. a company can use any software they want in their server AS LONG AS they make use of certain key technologies and industry best practices and have a good process in place. (yes this means no more SaaS without a security team...or a founder willing to learn that shit, or an new company providing that service. You could make an exception for revenue below 50k /year or something if you really want)
That are the rough consequences I can see from regulation. Nothing too negative imo
On your side, we have the status quo. With dishwashers running linux and having directory traversal vulns
https://www.theregister.co.uk/2017/03/26/miele_joins_internetofst_hall_of_shame/ https://www.theregister.co.uk/2017/03/26/miele_joins_interne...
companies ROUTINELY storing passwords, possibly without any good crypto and facing no consequences if stuff just stops working https://www.wired.com/2016/04/nests-hub-shutdown-proves-youre-crazy-buy-internet-things/ https://www.wired.com/2016/04/nests-hub-shutdown-proves-your... or if your data gets stolen because of their shitty practices
- sillysaurus3 9y agoOkay, but you are massively underestimating the cost. I feel bad responding to your comment with essentially a one-liner, so even though it's late, here you go: "certifying your product as consumer or industry grade would need to be an efficient process and would probably add onto the cost of developing a product" does not at all capture how thoroughly screwed a new startup will be if they have to devote $60k to a pentest before even getting off the ground. That would have sunk Apple, for example. I don't think most people recognize or appreciate how brittle startups are at the very beginning. You're also assuming that there are two states: "secure" and "not secure." You're further assuming that there is a way to transition from one to the other, by "becoming secure" through some state-mandated process. But it just ain't so. No matter how much money you throw at it, you can only increase security, you cannot prevent security problems. If you've shipped code, you've probably introduced some security problems. We should still try to improve the situation, but it is nearly impossible to make software secure. And in the meantime, it's the perfect tool for competitors to stamp out competition, since only incumbents can afford to be labeled as "secure" (when they're not). I don't think it would significantly curb the power of DDoS attacks, both because DDoS attacks are an inherent problem with the web's design and because hackers are always finding new and innovative ways to increase their DDoS power anyway. Some IoT devices aren't going to make a huge dent in their abilities in that regard. What would help is if pentesting became a regular occurrence due to massive cost reduction. It shouldn't take $60k for a pentest, but it does. The way to achieve this is through open-market competition. Regulation will only raise the price. Regarding your first point, I could take the easy route and say nothing. It's tragic when anyone dies. But it's also a fact of life. Many people will die to self-driving cars, yet there will be many thousands fewer deaths thanks to them. The idea that a single human life is more valuable than raising the standard of living for everybody is as strange to me as it is to you that a single life isn't the most valuable thing. Obviously, my perspective would probably change if someone close to me died due to some fool's bad software. But in that circumstance, the justice system would be as available to me as it is to you, and it was designed for just such an occurrence. It would not offset the heartbreak I'd feel, but at least society has processes in place to do something. this is me seeing the implied "but we can deal with it worse if startups fail" This seems self-evident: Many of the enjoyments we take for granted are thanks to startups. Our quality of life has dramatically improved due to the technology they help usher in. Technological progress is not nearly as inevitable as everyone would like to believe, and it's easy to forget how much better our lives are thanks to it.