5 ms·
Why? The person you are replying to outlined one major example where IoT security was improved: wireless routers. Not allowing users to update the software on t
by CameronNemo 3y ago
Why? The person you are replying to outlined one major example where IoT security was improved: wireless routers. Not allowing users to update the software on the hardware they own is just a botnet waiting to happen.
- dboreham 3y ago99% of users don't know their iot devices have firmware nor that it can be updated.
- computerfriend 3y agoMaybe that figure would change if the firmware could indeed be updated.
- NegativeK 3y agoIt would change, but again -- it wouldn't be appreciable. Security policy is needed that accounts for the behaviors of the vast majority of users.
- Larrikin 3y agoUsers update their phones, there's no reason they can't be educated to update their other devices
- NegativeK 3y agoMost non-technical users that I know don't actively update their phones and push back when I tell them that they need to do so faster than the automatic process because of an actively exploited vulnerability.
- CameronNemo 3y agoThey may have trusted family members, friends, or neighbors who they feel comfortable allowing the management of their internet connected devices.
- charcircuit 3y agoNo. As long as their iot device is still working consumers could care less about security updates.
- CameronNemo 3y agoWhat do you mean by "no"? Are you denying the existence of my grandparents who trust me to manage their devices?
- navigate8310 3y agoThis approach may function effectively with your close family members. However, it can sometimes fail when your cousins won't let you near their IoT devices because they view you as the hacker or tech enthusiast who might tamper with their gadgets.
- CameronNemo 3y agoSo what? Just because there are some atypical people doesn't make it a "no".
- charcircuit 3y agoI am saying that people like you are not enough to help the 99% of people who have an iot product.
- CameronNemo 3y agoApart from Smart TVs, most people don't have an IoT device to begin with.
- i_am_jl 3y agoSmart speakers, printers, thermostats, light bulbs, security cameras, door bells, locks, smartwatches, TV sticks...
- michaelt 3y agoFree software firmware would be great for free software lovers and tech experts, no doubt. But sophisticated users who'll take advantage of things like that are only 1% of the market. But if the aim is to stop DDOSes from botnets of poorly secured IOT devices, we need something to help the other 99% of the market.
- trelane 3y ago> But sophisticated users who'll take advantage of things like that are only 1% of the market. Most folks can't or won't do lots of things in their lives (e.g. plumbing, electrical, construction, lawn services, Automotive). The main thing blocking routers and IoT devices is the control every vendor wants to hold over their customers' devices after sale.
- i_am_jl 3y agoEven if you give control to the users, it's up to them to use it. I'd argue that the main blocker to IoT security is the lack of culpability on the part of device manufacturers. I don't want to go so far as to suggest that companies should be wholly liable for software bugs, but vulnerabilities that are brought to the attention of the company privately or disclosed publicly absolutely should be their responsibility to address. For you or me (or most of the folks here I suspect) we feel better if we had the ability to decide what software our fridge runs, but for 99% of people they're better off if their fridge's manufacturer provides them with regular security updates for the life of their product. That being said, these aren't mutually exclusive. In a perfect world we'd have laws compelling fridge companies to allow 3rd party software if they don't keep their firmware up to date.
- scj 3y agoI'd argue that in an ideal world, a fridge wouldn't have networking capabilities! Even if I don't buy one, I dread to think of what might happen if enough fridges across the world stopped working all at once (demand for non-perishable food and fridges would skyrocket). For the sake of consumer safety in our imperfect world, there should be a safe-mode hard switch fallback for any life-critical and/or high wattage device that gets networked.
- i_am_jl 3y agoI'm sure the number of routers running OpenWRT is dwarfed by the number of OpenWRT-compatible routers running vulnerable, stock firmware. Allowing people to install software on their hardware isn't a cure for vulnerabilities. It's a step in the right direction for sure, but it's a very small one from the perspective of something as huge as "IoT security".
- dtaht 3y agoWe have worked very hard in the OpenWrt and Linux projects to make it easy to update them in the field. Linux distros, android, apple, openwrt, etc have this facility built in now. IoT should also.
- i_am_jl 3y agoDevices should have the ability to run whatever software the user chooses. My point is that simply allowing this isn't enough to ensure those devices are secure.
- markhahn 3y agobut that's just because manufacturers desperately hide the fact that their own firmaware is based on OSS, and that there are alternate stacks available. imagine instead that vendors had to acknowlege the structure of their firmware, and make the (usually obvious) hardware interface documented from sale. that would automatically solve the issue of out-of-support(-by-vendor) hw.
- notatoad 3y agoreplacing the firmware can allow knowledgeable users who want to secure their devices to improve the security. it can also allow malicious actors to replace the firmware (or trick users into replacing the firmware) with something less secure. allowing users to replace the software on the hardware they own is also a botnet waiting to happen.
- sroussey 3y agoThe solution without free firmware (and I don’t like this) is that the device bricks itself at the end of its scheduled lifetime. Which is to say, you are buying a multi-year lease up front. And the manufacturer should send you a recycling return box. This is a more honest way to sell these devices. Consumers that would not care about length of security updates will suddenly very much care how long their “lease” is… and manufacturers would compete on the length of that lease (which is where the FCC could require security updates for the length of the lease period).
- yjftsjthsd-h 3y agoThat just forces e-waste. Aftermarket firmware lets a device stay useful indefinitely.
- dtaht 3y agoAgreed. I fully expect to see the routers we used in the cerowrt project from 2008 still operational for 10-20 more years. Thereś one out there with 4+ years of uptime that I know of. https://blog.cerowrt.org/post/an_upgrade_in_place/ https://blog.cerowrt.org/post/an_upgrade_in_place/