13 ms·
Even though many people scoff at the idea of government regulations, the economic incentives in IoT security are really all messed up and it's not really clear
by Asdfbla 9y ago
Even though many people scoff at the idea of government regulations, the economic incentives in IoT security are really all messed up and it's not really clear that the market will fix itself because so much of the damage can be externalized somehow. Does the manufacturer of a cheap and outdated IoT device care if it's participating in some ddos attack? Or like Schneier said, does the consumers care if they don't notice?
There seem to be some soft mechanisms that governments could explore. Maybe something like demanding opening the source code once security updates for the device stop, so consumers could help themselves. Or at least, an even more modest regulation, simply allowing all consumers to hack their own devices without fear of violating any laws.
One thing that could hurt the market is maybe making manufacturers liable for the damages caused by security holes in their devices, but regulation doesn't have to go that far to make an impact.
- maltalex 9y ago> opening the source code once security updates for the device stop, so consumers could help themselves That might help the readers of HN, but not users in general. Most users won't bother installing security updates for their PC if it's not forced on them. Updating one's light bulbs with something off github is a non-starter.
- kbenson 9y agoIt could help the market. It wouldn't be that hard to scan your local network and gather devices and firmware versions (if supported) or fingerprint them if all else fails, and compare against a database of known bad versions and provide weekly or monthly reports by email. I could see this being offered as a selling point of routers. AT&T and Comcast would almost definitely include support in their modem routers just for the extra protection it provides for their networks (and the extra data it gives them about every customer... I'm sure Comcast would love to know the number and types of Rokus and Fire sticks people had, if they aren't already doing this). Edit: To complete the thought, it's not generally that hard to flash devices that support it, so a report that says "X,Y and Z have exploits, here are some options" could go a long way. Making devices support some minimum standard of local upgradability would help immeasurably.
- maltalex 9y agoI'm sorry, I don't understand. Who's going to update the firmware in your light bulbs using a patched open source version of the manufacturer's code? Edit: > it's not generally that hard to flash devices that support it, so a report that says "X,Y and Z have exploits, here are some options" could go a long way. Making devices support some minimum standard of local upgradability would help immeasurably. You're right, it's not hard. But can you imagine regular users doing that? Anti-viruses, Microsoft, Apple, Google and all major browsers had to automate and force updates on users to keep devices secure. I have a hard time believing that any significant portion of users will flash updated firmware onto IoT devices to fix security vulnerabilities. Heck, when was the last time you checked for firmware updates for your home router? I do this stuff for a living and I don't think I've updated my (current) router's firmware more than once in the last few years.
- kbenson 9y ago> You're right, it's not hard. But can you imagine regular users doing that? Anti-viruses, Microsoft, Apple, Google and all major browsers had to automate and force updates on users to keep devices secure. If you've already got a database of router versions, it's not hard to include how to submit a new firmware version in that database, whether it be a POST URL, any params and the expected payload(s) or a TFTP upload. At that point, the same device that generated the report could give you a management page that listed some options and semi-automated the process. Want to update fridge with out of date/exploitable firmware with community fridge firmware X? Click here. Want to update with community firmware Y? Click here. Want to update to newer/latest proprietary firmware? Click here. I do agree it's not a solution to the problem. But it might help. It would also allow your techie friend to run an app on their phone or laptop when they come over and let you know, or handle it for you with a minimum of fuss. This problem won't ever get better until someone starts being held accountable for exploitable network attached devices. I think part of the reason that doesn't happen is because it's not feasible with current norms of behavior to expect producers nor consumers to do so with any level of confidence. Providing tools for this may take us one step closer. Personally I think a blend of regulations will be required. If devices sold are required to be updatable in one of a few ways, and workable firmware open sourced if obsoleted (or clearly marked or all labeling as may be entirely unsupported after 20XX), then it becomes feasible to require users to have some level of accountability over what they put on their local networks. I think it's the same as cars and the public road system. Cars have to adhere to certain standards to be street legal, and car makers must adhere to certain standard to sell their cars as street legal. > Heck, when was the last time you checked for firmware updates for your home router? Every 6-12 months, generally when I'm checking why performance is bad at the moment. But I'm not getting a report, so I only check when it's on my mind.
- elihu 9y agoIf it's at least theoretically possible for a knowledgeable user to fix their devices, that's a pretty big improvement over it being a totally unfixable black box. For something like a lightbulb most people wouldn't bother, but if it's something like a car, a person without the technical skills to fix it themselves can pay someone else to do it.
- retailbuyout 9y agoIt’s an improvement ideologically, I suppose, but not a practical reduction in economic damage potential. In a very real sense it doesn’t matter it you have quit making something seriously damaging if you need to disable millions or hundreds of millions of devices—ie some automatic update functionality is in itself hugely more helpful than just opening it. Ideally we would have this suggestion in addition to a stick to ensure people have an incentive to sell relatively secure hardware.
- katastic 9y agoThat's missing the point. Third. Parties. We have them for practically everything. End users can't figure it out, the manufacturer (say Microsoft) doesn't give two craps, so a third party (>90% of my career) involves solving those problems for users. If things were open sourced, that'd make my job insanely easier in terms of man hours invested in any project. I've literally had to spend >100 hours diagnosing that Dynamics CRM 2013's main data import tool has a bug that they refuse to fix. (Ever since it launched.) The import wizard refuses to actually load TIMESTAMPS (as well as some other columns) in even though it specifically supports setting that column. So when you do a data import, ALL of the user's data is out of order. That's completely unacceptable for any business to have their e-mails, notes, all have the same timestamp and no proper ordering. So "all" you have to do is first diagnose that this is the problem, then find this super obscure website where a guy made a fix except his code is half completed and full of errors, then install the entire CRM SDK stack. Learn how to write a C# plugin that exploits the CRM SDK. Write the corrected version of this guys code. Compile it. Use the CRM SDK toolkit to "attach" the plugin to your CRM. Figure out (no docs) what messages/events the plugin is supposed to actually trigger on with no error messages (while it takes >5-10 mins of user input every test to find out if it worked and then remove all the data again from the DB.) If that was open source, that'd be a one line of code fix and I wouldn't have to play the "prod the black box" game of trying to figure out exactly where the failure point is. Hell, just adding a debugger would be insanely powerful. And that was just "one" story I have with "one" product that I support out of dozens if not hundreds. So that's the thing. Regardless of whether a manufacturer open sources or not, people like me still have to fix the damn problem. Failure isn't an option. The checks have to go out. The lung machine has to keep blowing. And whether or not the business makes it easy or hard, doesn't enter the equation (except in terms of cost and man-hours). Nobody cares that you want to protect your IP. They care that their damn time clock doesn't work and they've got millions of dollars of product to ship while their employees stand outside of a locked automatic door. So the real question is simply: Do you love, or hate, the people who support your software? Because we're still here, every day, slogging through insane problems by poking blindly in the dark. Closed source software breaks just as often as open source. The difference is, that the essential third-party (me) has to bill 10X as many hours to fix the problem. So if you're a business, it's in your best financial interest to demand open-source code whenever not prohibited (security constraints, HIPPA, whatever). Closed-source is like buying a car and pretending it'll never break down, or that the manufacturer has the time, energy, and willpower to come down to your house and fix it. Some might go that far. The other 99% won't. And if there's a piece of software that has zero bugs, I haven't seen it in my lifetime. So to bring this back to IoT. When a clients IP Camera goes down, they don't give a crap why. They need it back up. Yesterday. And they especially don't appreciate buying expensive hardware that ends up having security flaws... and worse... that is physically impossible to close. The clients aren't going to easily understand, "I paid $3,000 for it, and it works fine, but I should NEVER use it because it could be hacked?" That's like buying a car and a recall hits that says "the locks no longer work" and instead of fixing the locks, or allowing a third-party to fix the locks, everyone is just supposed to stop driving their car. You'd never see that in the real world, but somehow "software is magic" so it plays by different rules.
- dotancohen 9y agoThat right there is the problem that regulation is meant to solve. The manufacturer is the one in position to enable ease of _secure_ updates. Right now the manufacturers are not doing that. Try walking into Home Depot and asking the salesperson how to update the firmware on the lightbulbs he is selling. You will get your sanity questioned, especially once you explain _why_ it is important to update.
- AnimalMuppet 9y ago> One thing that could kill the market is maybe making manufacturers liable for the damages caused by security holes in their devices, but regulation doesn't have to go that far to make an impact. What reasonable case is there for making them not liable for the damages caused?
- Asdfbla 9y agoYou're right that they should be liable, but pragmatically it's maybe too much of a risk for smaller companies to face some potentially frivolous lawsuit for millions of damages supposedly caused by a ddos originating from some of their devices or something. Surely the right idea in principle, though. I'm just not sure how realistic is it to implement in a smart manner.
- bcg1 9y agoThat's what the insurance industry is for. Just make the companies liable, and they will seek insurance. Insurance companies will force them to take reasonable measures in order to carry a policy. Nothing new under the sun.
- thephyber 9y ago> What reasonable case is there for making them not liable for the damages caused? After what period of time? Microsoft updated Windows XP after the official end-of-life of the OS for consumers with the patch to the Samba protocol to prevent WannaCry, but if they hadn't bothered, would they still be liable? Should they? Are they obligated to update pirated versions of their OS? Is the manufacturer liable if they release a software patch but the product owner doesn't apply the upgrade? What share of the liability should each party take? Software is largely immune to liability litigation in the USA because the current legal status of it is not legally "a product". Converting it to "a product" for the purposes of liability is a major sea change for our understanding of what business models can be applied to software, licensing, ownership, etc. Also, does the average product programmer carry some sort of programming insurance? Are we going to force every web developer and every open source programmer to carry insurance, to be licensed to program, and to live up to specific ethical standards? I'm not saying these are undesirable changes, just that they are changes and there are a ton of issues programmers don't foresee that should be discussed before making
- wmf 9y agodemanding opening the source code once security updates for the device stop They probably don't even have the (usable) source code.
- mtgx 9y agoArm recently announced an open source firmware for IoT devices. Now all it takes is for OEMs to want to replace their proprietary firmware with this (while keeping all bits open source as they extend it). https://www.arm.com/news/2017/10/a-common-industry-framework https://www.arm.com/news/2017/10/a-common-industry-framework
- confounded 9y agoWell, they probably would if they had an incentive to do so.
- zby 9y agoMaybe we should mandate that a reasonable source code is deposited somewhere?
- wmf 9y agoAnd you'd only discover that the code doesn't even build until it's too late.
- tzs 9y ago> One thing that could hurt the market is maybe making manufacturers liable for the damages caused by security holes in their devices That's what insurance is for. Something like this was discussed in my torts class in law school, except that was long before IoT devices existed so it was about things like lawn mowers. The idea is that it might make the most sense economically to make the lawn mower manufacturer liable when users cut off a finger or toe, even if it was due to consumer stupidity instead of any negligence on the part of the manufacturer, because the manufacturer is in the best position to estimate the risks and purchase insurance to cover them. Presumably, the manufacturer will pass on the costs of those insurance premiums to the consumers. The manufacturer still has an incentive to try to build safe mowers, because if their insurance company ends up paying out a lot the premiums will go up. They can pass those higher premiums on to the consumers, of course, but that will make them more expensive than their safer competitors. The manufacturer is in a good position to deal with insuring for these injuries because they know how many mowers they are selling. Other candidates have less useful information. For example, a consumer usually has no idea what their chances are of suffering a lawn mower accident, so have no idea how to decide how much insurances is needed. Health insurance companies will have a good idea in the aggregate of how many of these accidents occur in a year, but they have no idea which of their customers use lawn mowers. Done right, this should not hurt a market much. I'm not sure it could work for IoT, though, because a lot of IoT devices are made by new companies that probably will not be around long. With things like lawn mowers, you could takes years to get around to cutting your hand off, and still reasonably expect the manufacturer to be around. Not so with a lot of IoT devices.
- heavenlyblue 9y agoHow do you deal with insurance fraud if the manufacturer is the one paying for the insurance?
- cobbzilla 9y agoIf a manufacturer engages in fraud and is caught, they would (a) be subject to criminal penalties for insurance fraud and (b) it would become very difficult or expensive for them to acquire insurance in the future. These two negative consequences serve as a strong deterrence against fraud.
- rogerbinns 9y ago> maybe making manufacturers liable for the damages caused by security holes in their devices Then they will sell two versions of the same product. One lets you voluntarily waive that requirement for the same price as today, or a "normal" version where it costs orders of magnitude more.
- userbinator 9y agoIndeed, I have the feeling that all regulations will do is lead us down the slippery slope of regulating all software and computing devices, eventually creating the dystopia predicted by RMS in his famous story: https://www.gnu.org/philosophy/right-to-read.en.html https://www.gnu.org/philosophy/right-to-read.en.html Or at least, an even more modest regulation, simply allowing all consumers to hack their own devices without fear of violating any laws. More simply, they could make all reverse-engineering legal, but then the copyright/IP lobby would strongly oppose.
- jimktrains2 9y ago> Indeed, I have the feeling that all regulations will do is lead us down the slippery slope of regulating all software and computing devices, eventually creating the dystopia predicted by RMS in his famous story: https://www.gnu.org/philosophy/right-to-read.en.html https://www.gnu.org/philosophy/right-to-read.en.html Unless said regulation was the ability to actually own your device and install your own firmware, doubly so once it becomes unsupported?
- jpalomaki 9y agoTreat security issues as defects in the product and apply normal consumer protection laws. Put pressure on ISPs to make them take responsibility for traffic originating from their networks. They have the the tools to notify customers if customer is sending suspicious traffic (and if necessary, they can temporarily shutdown the connection).
- trowaybloway 9y ago> demanding opening the source code once security updates for the device stop Copyright law is not in agreement with this. Reasonably, a manufacturer could argue that follow up installments of the software are still actively sold. Then one question is why the fixes wouldn't be ported back to the old release and I guess because differences in the code require significant effort to adapt the fix. Regulation should seek to equalize ... > manufacturers liable for the damages caused by security holes in their devices This is not easy if a chain of bugs in different programs is used to create an exploit. And it would be damaging to warranty wavers especially in open source. After all, the server side will likely run full fledged open source stack. This is where service providers step in. Google would probably like to do monitoring and instrumentation as a service, among others.
- _pmf_ 9y ago> because so much of the damage can be externalized somehow It's interesting to see how the US citizen ordering the product of a back alley company in Shenzhen via Alibaba is supposed to recoup his damages. It's impossible, period. With wired IoT devices: segment your home network, always use a trusted gateway application and never allow your IoT devices direct WAN access. With wireless devices, all bets are off, since you don't know at all who can access them (i.e. they can interpret WiFi frames in unassociated state directly in silicon, and you'll never now, even if your stack is completely open source) if they are in the vicinity.