4 ms·
If they can be bricked, perhaps they should be bricked. Maybe this is something we should encourage going forward to encourage security for IoT? Maybe we should
by devoply 7y ago
If they can be bricked, perhaps they should be bricked. Maybe this is something we should encourage going forward to encourage security for IoT? Maybe we should hold a Brickcon where security researchers try to develop ways to brick any insecure devices before they become a threat.
- adrianN 7y agoBefore you do this, please make a law that forces the manufacturers to replace the devices free of charge when they get bricked due to a security problem.
- Groxx 7y agoClass action lawsuits can be pretty effective at achieving this.
- tty2300 7y agoHaving a known security bug unpatched for longer than x days should be grounds for a warrenty refund. That should get companies moving when there is a real world cost for not dealing with security bugs.
- taneq 7y agoSounds like a grand way to ensure that nobody is willing to take the risk of building internet-enabled devices in the first place.
- mprev 7y agoYou mean like how no one builds medical devices?
- taneq 7y agoGreat comparison. I'd really like my wifi-enabled light bulbs to cost $27,499 each.
- TeMPOraL 7y agoMight be somewhat ironic comparison. Apparently the problem of garbage companies doing garbage devices exists in medical space as well; see e.g. [0]. Also, it's not about making wi-fi light bulbs cost thousands of dollars, but if yours were on the cheap end, they are most likely garbage products with highly intentional planned obsolescence, and subsidized by data collection app you have to install, which is the whole point of making them in the first place. If such business model were to become unprofitable, I believe it would be a great win for the society (and the environment). -- [0] - https://www.theguardian.com/science/2018/nov/26/uk-firm-sold-spinal-implants-disintegrated https://www.theguardian.com/science/2018/nov/26/uk-firm-sold...
- mcv 7y agoIt's all part of a trade-off. Does the world need wifi-enabled lightbulbs that increase the size of criminal botnets? If not, then our options are to either stick to non-wifi-enabled lightbulbs, or ensure that our wifi-enabled lightbulbs cannot become part of botnets.
- SmellyGeekBoy 7y agoManufacturers already have to replace devices when they're bricked by a hardware problem. They have various quality control processes in place to try to prevent this from happening. I don't see why it should be any different for security - or make a huge difference to the cost.
- adrianN 7y agoSounds like a good way to not have an army of botnets threatening the rest of the Internet because people are too lazy to walk to the switch...
- deadbunny 7y agoGreat, the IoT is bullshit. A NoT is much better.
- darkpuma 7y agoMission accomplished. IoT is a euphemism for e-waste.
- pjc50 7y agoIn the UK I would argue that's already covered by consumer law, if the insecurities can be considered a "manufacturing defect".
- deleted 7y ago[deleted]
- bifrost 7y agoEhhh then Linux would be considered a manufacturing defect....
- avian 7y agoNo vigilante justice required. Just make the companies liable for the damage they cause when their products turn into a botnet. Why can't products have a "declaration of security", like they have for EMI compatibility, safety standards and other such things? Declare that the manufacturer has taken reasonable steps to make the device secure and is liable for damage if that turns out to be untrue.
- kyeb 7y agoGood luck enforcing something like that.
- avian 7y agoWhy is enforcing this so much different than enforcing that your cheap Wi-Fi router doesn't interfere with air traffic control radar?
- Groxx 7y agoBecause your wifi router is limited to a minuscule physical range. The rest of the world's wifi routers don't continually threaten to interfere with your local air traffic control radar - if they did, we'd probably have much stronger controls around it than we currently have.
- birdman3131 7y agoIt is a prove a negative vs prove a positive. "This device cannot broadcast with enough power to interfere with radar" is provable. "This device has no security holes" is often not provable even if they try to secure it.
- yetihehe 7y ago"This device uses [x,y,z] techniques for avoiding [interference/hacking]" is provable. List of required techniques should be known in advance (like ["no default password", "no raw tcp password sending", ...]). I have seen such requirements when delivering devices for some big companies which care about security of devices reselled by them, I think it was even some publicly defined standard, but can't find it now. Such things exist already, but are just not enforced like interference requirements.
- taneq 7y agoOr perhaps they could be fixed? There are plenty of examples of worms released with the express intent of patching a particular vulnerability (https://en.wikipedia.org/wiki/Anti-worm https://en.wikipedia.org/wiki/Anti-worm)
- mcv 7y agoThat is awesome. Probably still illegal, but having viruses and worms that patch the vulnerabilities that they use to spread, is a million times better than viruses and worms that use those vulnerabilities to do more damage. It's a bit like guerilla pot hole repair crews: https://www.citylab.com/equity/2017/03/portland-anarchists-want-to-fix-your-streets-potholes/519588/ https://www.citylab.com/equity/2017/03/portland-anarchists-w...
- bifrost 7y agoAs annoying as it is, I agree. Brick devices that are known malicious.