4 ms·
There might be another way. I heard from "Security Now" podcast that there is a new law that require all government purchased IOT devices must be update-able t
by srcmap 9y ago
There might be another way.
I heard from "Security Now" podcast that there is a new law that require all government purchased IOT devices must be update-able to fix security issue.
Expand the law a bit:
Make all internet connected device makers (Include phone maker) liable for any loss of private consumer info, hack for 10 years from any internet connected devices release.
Anyone can file lawsuit against them easily or in class actions against the vendor if they don't provide security fixed/upgrade within 4-6 months of from being notify of the vulnerability.
Establish an ISO security standard for IOT (and all Phone): such as
1) Standardize SW/FW update requirement, method and audit. ssl, security hash, CA, etc.
2) Requires system to monitor and log all program/critical system components creation/execution/all internet connection and download for auditing by owner of device.
3) Require system vendors to have source code / tools chain / build system in place to rebuild and fix security issues.
Once the vendors are liable for hack. They will need Insurance. The Insurance Company can follow the ISO security standard to audit and estimate the potential cost.