11 ms·
Japanese government will access home devices in security survey
- jbeales 8y agoThis seems like exactly what some commenters were asking for in the "I Scanned Austria"[1] post 9 days ago. This seems like the digital version of checking for locked doors. Here in Montreal you can get a ticket for leaving your car door unlocked. This seems like a similar initiative, but one that protects against greater threats while being less punitive. [1] https://news.ycombinator.com/item?id=19113147 https://news.ycombinator.com/item?id=19113147
- tokyodude 8y ago> you can get a ticket for leaving your car door unlocked What is the reasoning behind that law? I know plenty of people who live in areas where they don't lock their house because they believe it's safe enough not to have to lock it. And besides, anyone who really wanted in could bust the door down or break a window. Same with cars. I've had my car broken into 5 times in LA/SF. They busted the window each time. Not locking would have solved nothing although maybe it would have saved me having to pay to get the window replaced. Ideally if the law is about preventing crime it seems like they should actually try preventing the crimes rather than tell citizens to change their lives. Here in Japan pull out car stereos are not a thing and they have large car stereos that are not available in the USA. They are not available in the USA because they're too large to carry and would get stolen. I'd prefer to live in a society that protects it's people's lifestyles than one which tells them "that's the way the world is, lock your stuff up" Not sure that made any sense. There's plenty of things you can do in Japan you can't do other places because the crime level is high in those other places. The attitude of those other places is "crime exists, there's nothing to be done about it, so suck it up". Living somewhere where the crime doesn't exist (or is low enough to ignore it) opened my eyes that I was in a a bubble of "crime is the way things are". Now I see that no, it's the way we let them be. I'm sure it's more complicated than that.
- close04 8y agoThe idea is that you are costing the police valuable resources for something you could have easily avoided by locking the car. Many countries have such laws. You have to take the proper precautions or face a fine. An open door is seen as an invitation even for a thief that normally wouldn’t risk breaking a window. Basically for crimes of opportunity. And this applies to houses, cars, etc. Insurance companies will see it the same way.
- Gpetrium 8y agoNot only will it cost the police more, but it also costs the car insurance and by proxy everyone that is insured. If 100 people leave the car unlocked and are robbed and on average the car costs $30,000, this will cost $3,000,000 + insurance resource + customer hassle + police resources + judicial resources. That is a steep cost to all parties. (Dis)incentives are more successful when it considers all actors.
- codefined 8y ago'Smashing a window' is unlikely to incur costs of $30,000, perhaps $300 is a better estimate. I would also argue that insurance resources, customer hassle, police resources and judicial resources are also all roughly equal for handling stolen items from a car, versus stolen items from a car + window broken.
- close04 8y agoYou’re ignoring the fact that an unlocked door greatly increases the chance of the crime happening in the first place. It won’t cost more but it will make it happen more times. Many opportunistic thieves will simply try the door and only go in if it opens.
- EpicEng 8y agoIn what world does a broken window total a car? While we're at it, in what world does your insurance premium not increase drastically after you collect on a claim? Your math is incredible flawed?
- inherentFloyd 8y ago>Here in Montreal you can get a ticket for leaving your car door unlocked. Here in the US you get robbed when you leave your car door unlocked. Kind of a punitive measure in its own way.
- coryrc 8y agoIn some parts of the US, you get your window broken when you leave your car locked. Unlocked, your stuff just gets ruffled because you know not to keep anything worth money in the vehicle.
- Johnny555 8y agoIt's true - when I used to park on the street in SF, I left my doors unlocked after multiple break-ins through the windows. I had nothing of value in the car (not even a car stereo, it was stolen and I never replaced it), but apparently they didn't believe me and wanted to break in and check the glove compartment and center console to be sure.
- tzakrajs 8y agoPeople just break your windows anyways because they don’t expect the door to be unlocked. Have heard this anecdote from friends twice. Also the people breaking into cars aren’t typically the most sober or mindful of detail. I had my car broken into a little while ago and they stole a bag of tools on the seat but ignored a like new MacBook Pro on the floor of the car. The point is that you can’t win and should enjoy losing.
- mef 8y ago> the institute will ensure no data is leaked that’s a relief
- celeritascelery 8y agoIf only more companies would decide to do that.
- shok3001 8y agoI can't tell if this is sarcasm or not.
- b_tterc_p 8y agoIf we assume that their intentions are as stated (maybe you don’t), they don’t have much of a reason to store any of the data they extract.
- DINKDINK 8y ago"We take your privacy and security very seriously"
- NZiozis 8y agoThis may seem weird, but I think the idea of what they're doing is spot on. If anyone were to get access to my things I'd rather it be the government and then have them disclose it to me. Additionally, if you don't want your information accessible you've had your notice to hire someone to lock it down or lock it down yourself. I would liken the service to the government checking the insulation on your house.
- azinman2 8y agoAs long as you trust your gov.... I think Japan is probably in better relations with its citizens than most countries...
- icebraining 8y agoWell, if you keep insecure stuff available to the world, you're trusting everyone with it, including every government.
- crankylinuxuser 8y agoPrecisely. It depends on what kind of actions they wish to do with the resulting scan/hack. If they offer services to secure people/companies free or cheaply, then its a overall large positive. If they give it to their equivalent NSA apparatus, that's a major bad.
- bg24 8y agoAgree. Skillset and response will determine the success. Japan govt has a good precedence of centralized security scanning for country’s Internet, so hopefully it is a positive. Vast majority of Internet users are not security savvy. Doing a baseline scan with appropriate remediation guidance will go a long way.
- eeZah7Ux 8y agoGiven that they are announcing it instead of doing it secretly they seem to be starting with the right foot... I'm pretty sure security researchers will set up honeypots and monitor what the government probes are doing.
- porphyrogene 8y agoThis is an interesting and innovative approach. It is essentially a grey hat operation carried out by the government to raise individual awareness about cybersecurity. Considering that the article mentions a "constitutional right to privacy" I'm assuming that citizens would have significant recourse if one were to prove that one's data were leaked. It is ethically dubious but as an American whose phone calls can be tapped at any time without a warrant I am open to the idea that it is time for radical measures to improve privacy.
- ganzuul 8y agoHave you ever had a device responding to ping that documentation says runs an old version of Windows NT, while the last version was released 10 years ago, and you have no idea where the machine is physically located? I could imagine a lot of businesses will open a closet to find the source of that infernal beeping, and discover a computer they forgot about.
- arcaster 8y agoWhy would anyone ever be okay with this? Regardless of the country or soft the culture is - this should never be seen as "okay" or "passive" in any way.
- alias_neo 8y agoIt's a difficult choice. In a way, you can see it as a free pen-test on your network. I don't even think it's a case of trusting them, because if they get access to webcam data or something else that they shouldn't, assume someone with less well-meaning intentions can and has also done so.
- arcaster 8y agoYeah - this is exactly the root of what I'm getting at. Nobody really know's who "the government" really is. They're so bad at keeping their own secrets secure and in the right place - I sure as hell don't trust the least common denominator among gov't employees when it comes to privacy and ethics to have anywhere near the kind of observation into my life they already have from a squad car filled with feds and a telephoto lens...
- alias_neo 8y agoWell, in this case, it's the NIICT (National Institute of Information and Communications Technology) and it sounds like their efforts will stop at rainbow-tabling the devices such as IP cameras etc, to see which have default credentials or weak credentials. The problem is that the normal, every day people who run these devices, on the most part, don't understand that not only are they open to the internet, most manufacturers provide Dynamic DNS making it painfully easy to search for them. Further still, these manufacturers set the same default password for every device. Some have been known to leave the "empty" credential slots usable. Due to poor programming, you could simply login with no credentials at all. I have to agree, I'd be hard pressed to decide whether I would or wouldn't accept this "survey", but, with notice, like people are being given here, you can mitigate the risks (cover the cameras, remove the data etc) and be told there are weaknesses in your system, or alternatively, not know and have some unknown accessing them at any point they wish, for any reason they wish.
- secfirstmd 8y agoWell the five eyes, Chinese, Russians, Israelis, French and many private actors are doing this all the time anyway. May as well see what happens if a Democratic government tries to do this for a positive reason.
- _bxg1 8y agoI interpreted this headline very differently at first
- kmlx 8y agothe following article puts it in context a lot better: https://www.ft.com/content/7d57b8d8-294e-11e9-a5ab-ff8ef2b976c7 https://www.ft.com/content/7d57b8d8-294e-11e9-a5ab-ff8ef2b97... "The huge question is what happens if, as many experts suspect, the experiment reveals major vulnerability throughout Japan. Even that shock may not do the trick. There is an awful lot of complacency to shake off and while Japan is far from alone in that, all the top-down, Society 5.0 posturing makes it hard to shift. Even with the government’s pro-IoT drumbeating in the background, said Itsuro Nishimoto, the president of Japanese cyber security group LAC, the business of IoT security is not yet growing in Japan. There remain deep, unresolved questions of whether manufacturers of IoT devices or their users should have responsibility for ensuring security and a nagging concern that the government’s mega-hack will not conjure up an answer."
- argd678 8y agoWhat this says of course is that software vendors and security vendors are not able to or not incentivized enough protect their users, to the point the government needs to become more involved. The biggest issue I see with almost all security software is that they have no idea what should or shouldn’t happen and the just punt to the user asking them to be a SME on the right behavior, and with enterprise software that’s so complex there’s no way to know if the millions of settings are what the business really intended, and very little software even allows you to express intentions beyond a low level allow deny rule. Google docs is a little better in that they talk in terms of what you’d do with a doc, but very little software is even at that basic level.
- cced 8y agoCan you expand on Google’s approach to “allowing users to do X with a Doc” ?
- argd678 8y agoThey allow for high level intentions like “only share this doc within my company”, or “share only with specific people”. Connecting the permissions to the way someone thinks about it, going more in this direction is what’s lacking IMO.
- microcolonel 8y ago> What this says of course is that software vendors and security vendors are not able to or not incentivized enough protect their users, to the point the government needs to become more involved. I think it says something more specific to Japan than that. If you go on Shodan or do your own scans and compare Japan to other technologically advanced nations, you'll find a hell of a lot more random internet-exposed IP cameras, printers, etc. Do a quick search for the Server response header from a Brother printer, and you'll see what I mean. The way that people use computers in Japan is very different from how people use them in the West. I suspect that the way the organizations are structured, and the way that crime works in Japan, are a likely source of this difference.
- DINKDINK 8y agoSearches and Inspections in Noncriminal Cases https://law.justia.com/constitution/us/amendment-04/05-searches-and-inspections-in-noncriminal-cases.html https://law.justia.com/constitution/us/amendment-04/05-searc...
- userbinator 8y agoIt is not a big leap from this to "you have connected an unapproved device, we have blocked you from the network" to "you have been fined for connecting an unapproved device to our network" or worse... some of you here may be old enough to remember the monopoly Bell had on telephones and the times when it was illegal to connect anything they did not approve of. "The road to hell is paved with good intentions."
- general8bitso 8y ago...or the movie, ‘Brazil’?
- newnewpdro 8y agoThose who don't trust the government must already be assuming this is happening without their consent and taken the appropriate measures. So I don't really see a problem, if it results in citizens getting informed by someone other than their paranoid neighborhood tech-obsessed geek that their negligence is part of the problem. I've been that guy in the past, there's a substantial portion (majority?) of the American population that will pay far more attention to a government notice of vulnerability than a fellow citizen they perceive as a paranoid extremist dreaming up invisible threats.
- hatmatrix 8y ago> Institute researcher Daisuke Inoue says the project's aim is to increase the safety and security of people's devices. He says the institute will ensure that no data is leaked. Classic example of "what could go wrong"?
- xn1002 8y agoI would like to know where all the government shills came from in this thread. It's pretty unusual for HN.
- yVaoq10101 8y ago"A revised law that went into effect last November gives the institute the authority to gain access to people's devices over a five-year period." I welcome this. The government should protect its citizens from the external enemy. All measures taken are appropriate, and citizens should have full confidence that the government will not leak their nudes from their webcams. After 5 years the period will be extended for further protection of the populace. Finally homes are the safe spaces they were intended to be.
- kgwxd 8y ago"The institute says it will keep under wraps any data obtained in the survey." Unless someone better at scanning for vulnerabilities finds a hole in their system.
- achillean 8y agoFor an overview of Japan's current Internet exposure check out: https://exposure.shodan.io/#/JP https://exposure.shodan.io/#/JP