4 ms·
> Stop buying stupid disposable junk. I get the frustration, but this is a narrow perspective. _Consumer_ IoT is still waiting for some good use cases. But IoT
by wiremine 6y ago
> Stop buying stupid disposable junk.
I get the frustration, but this is a narrow perspective. _Consumer_ IoT is still waiting for some good use cases. But IoT touches a lot more industries than that: medical, earth science, manufacturing, heavy industrial, logistics, energy... they are all being improved with useful IoT solutions. And we need solid security in all these areas, not just the home.
I'd also note that privacy and security, while related, are separate issues. Most IoT solutions don't factor in either concern well.
- bsder 6y ago> And we need solid security in all these areas, not just the home. Who is we who need solid security? I haven't met them. They don't sign a check for security. They don't do anything other than put "Security" on a PowerPoint slide and forget about it. We make our shipping IoT stuff secure because it's a point of pride and point of competence. But we built the whole architecture around that idea, and it definitely slowed us down at the start. Until people start cutting checks for actually secure IoT, it's going to remain a giant field of cow dung.
- HeyLaughingBoy 6y agoThey really do exist. Believe it or not, just last week I had an actual meeting with an actual paying client who took IoT security seriously because "we've got some hydraulics on this machine that can cause real damage if someone hacks into it." Unfortunately, I think this is going to be the perspective for a long time: if the customer sees real liability (read: a lawsuit for physical damage) as a possibility, that's probably going to be the only motivating factor to take security seriously. Whatever. One step at a time!
- paranoidrobot 6y ago> Who is we who need solid security? Anyone with a modern medical device is the 'we'. My grandmother got a new pacemaker installed a while back. She now has a device sitting beside her bed with a 4G modem in it, that talks to her pacemaker at night and sends the data back to some service, which in turn her Doctors can access. This is apparently the normal thing to do. What level of security is there in either of those devices? How do you ensure that there isn't open ports? Does it get security updates pushed to it? (I wouldn't be money on that) How does one ensure that this can't send malicious commands to the pacemaker? This isn't just an issue with pacemakers, either - plenty of other medical devices are coming with various wireless chips in them.
- wiremine 6y ago> Who is we who need solid security? Ultimately, the we is society.