Your thermostat maybe wants to talk with your alarm clock. I can get that. But it does not have to happen over the Internet. Let them talk locally.
Your thermostat maybe wants to talk with your alarm clock. I can get that. But it does not have to happen over the Internet. Let them talk locally.
You and I know the basics of computer security. We can take a crack at designing a secure system and maybe do okay. But the argument goes like this: Yes there are security conscous programmers, but there are also many which are not. And those people work on products which make it to market. How do we stop those products from making it to market? Government intervention. He's given up on education and relying on the informed developer, and would rather rely on public policy. I find it a bit sad.
The government has a proven conflict of interest and disincentive to harden the infrastructure. Vulnerabilities are valuable for espionage. And there are already regulations like HIPPA, PCI, etc, yet there are still breaches. Regulation will add complexity to business and will protect market share for the entrenched players who can afford to follow it. That will lead to further consolidation and reduced competition while I feel that the opposite is needed.
The fiefdoms described in another post wouldn't be such a bad thing. At the nation state level, competition will also make for better security. Isolationism doesn't work out well in world history. Movement of goods and ideas does a better job at bringing countries together. I feel there's a pendulum swinging back towards isolationism but it goes back and forth over time.
Case in point: If a seller in one country can lower the costs of a good shipped to another country by scrapping responsible waste management in favor of polluting the commons (i.e., places where individual property rights claims are difficult to press), then "the magic of the market" is likely to increase - not decrease - the amount of pollution generated by the trade.
What libertarians don't like to admit is that they see free markets as more than ideal mechanisms for preserving efficient economies. They also see them as efficient sources of good and just governance. Like all belief systems, faith in the quality of governance supplied by free markets, while rational and well-supported to a point, can be taken to counter productive extremes where it maintenance stops operating like empiricism, and starts to function is ways indistinguishable from fundamentalists religions.
Not sure how many sensible knowledgeable people want this to be the dominant force in guiding global network security.
This is a pretty good argument the absolute value of principle, tbh
For what it's worth, I tend to see principles like map; useful - even indispensable - in many situations, that are nevertheless abstractions and therefor imperfect guides to actual reality. Use maps, yes, but avoid mistaking them - or any system of symbols - for the things they represent (i.e., the map is not the territory).
Indeed, principle is a form of proxy wisdom for the young and inexperienced. It's better than nothing, but probably not enough to save you from at least a few episodes of hard reckoning. Assuming these don't get you killed, the places where principle doesn't serve are the ones where mature judgement develops.
Granted, there's a point where this doesn't serve either, but that's okay too since mortality always wins in the end.
I mostly argue that myself where the problem is demand-side where customers don't put money into it. There's a few things on supply-side to factor in, though:
1. Companies lie to customers about how necessary these vulnerabilities are. They condition them to expect it. They also charge them for fixes. It takes almost no effort to knock out the common ones with only 30-50% premium for high-assurance of specific components. Even premium producers often don't do either with those that do so rare most consumers or businesses might have never heard of them.
2. Years of lock-in via legacy code, API's, formats, patents, etc means consumers often don't have a choice or only have a few if they want the modern experience. Many times specific choices will even be mandated by groups like colleges. Market created the problem that now lets it milk a captive audience out of money. It won't solve that problem no matter what they want.
These two, esp 2 given patents and First-Mover Advantage, are huge reasons the market alone isn't likely to fix things. Some regulations could deal with them. The market can also fix things where these two don't apply. The market can also be combined with regulations like with DO-178B market that regularly outputs high-quality software far as I can tell.
This was addressed in the hearing. Schneier says its a negative externality, like invisible pollution. The problem is that the consumers don't care because they aren't the ones getting attacked by their devices. Instead their devices are quietly using their residential internet connection to help DDoS websites. Would you pay $20 more to buy a different DVR that is less likely to annoy a random person you've never met over the internet? Most people don't care, and don't have the knowledge and experience to care.
Because consumers won't pay for it, the manufacturers don't bother to invest in security engineering. (These are low margin products after all). As a result we're all worse off.
The free market crowd lost all credibility after Enron, Worldcom, and the housing collapse. They had countless reasons why the above scenarios wouldn't happen. Reality proved their theories to be the complete and utter BS any rational human being could see from the start. In a utopian society a lot of ideas are great, unfortunately we've got reality to deal with, not utopia.
So that friction will always exist.
The market oppertunity is not for non-hackable thermostats but for more advanced internet routers which can do more advanced packet inspection under low latency.
That's not the same as "enforced regulation", but it certainly walks and cuaks like it. No direct government intervention -> No freely interconnected internet.
And what about consumer offerings ? There was no such restricitons. The simple reason an ISP did not create its own Internet because by connecting to bigger net it increased networksize and value of its offering. Thats how the whole world, not just US, settled on Internet.
The private networks are still making walled gardens with no innovation in fiber space with innovative, walled gardens in Internet space. Same old same old doing nothing of significance with pure self-interest unless building it on what government created and partly subsidizes. The latter groups usually also plateu into stagnation sucking profit while the open, less-selfish models grow in new ways.
Inviting governments to regulate Internet is unnecessery risk.
Internet is a set of protocols run on top of huge pipes that interconnect across many companies, nationalities, etc. They all speak common language. You're trying to oversimplify it to expand on your false argument. What I just described was only achieved once... by governments & companies making money off government projects. No private industry has duplicated it.
Closest thing was the cell phone industry where they limited what type of traffic, kept the bandwidth minimal for high profit, charged per amount of data, and so on. They eventually started looking more like the Internet by internally using Internet technologies funded by DARPA, NSF, etc. Originally, though, their model couldn't have created something like we see with the Web or Internet-run commerce. Just like MA Bell before them with their schemes.
Private sector wouldn't have built the Internet on their own since it's too risky and costly with 3rd parties getting most of the benefit. Government did it better.
"What someone builds on top of it and/or how open/close, It still does not negate that characterstics of Internet."
It does within what they build. Much of online activity has transistioned from purely Internet technologies to Web technologies. Companies like Facebook and Slack are where content and activity is going instead of HTML web sites and IRC. The result is people are locked in to vendors to just get what experiences they allow in their walled gardens. With most Internet tech, I could just move everything I had to a different client or server if what I was using wasn't good enough. Standard protocols existed to help. Private sector prefers the opposite as lock-in equals more money.
So, they fail twice: preventing something like the Internet from occurring until government did it; trying to turn it back into wall gardens of the past albeit with web browsers and more graphics.
I am not refuting this. What I am claiming is it was not neccessery despite being helpful. After the market made absolute [1] long distance communication and processing on data cheap and at large scale, it was only a matter of time. Even we had/were to go through IP level walled-garden/subnets, the world would have set on non-discriminating Internet.
Think of this way, what Govt. created/helped-created intially was a local network and only after thousands of ISPs coming together, not because of incentives from Govt, but because of demand we have the Internet as we know now.
> Companies like Facebook and Slack are where content and activity is going instead of HTML web sites and IRC.
Facebook, Slack, HTML, IRC != Internet. Question: Is someone being restricted from sending/recieving anypacket to/from any IP in the world ? If no then Its not walled-garden from Internet point of view. Internet is not being harmed in anyway. However bringing Govt. into this will most likely make the answer yes.
> So, they fail twice: preventing something like the Internet from occurring until government did it; trying to turn it back into wall gardens of the past albeit with web browsers and more graphics.
I am not aware of any IP level walled-garden. Facebook/Slack/Myspace/etc are/were in app/website business not Internet business.
[1] Not telephone etc which transform the data nondeterministically.
It still hasn't to this day in private services. They almost all wall off whatever they build. Those that build connections charge out the ass for them with all kinds of restrictions and schemes. Many get acquired and then crippled.
You need to justify your assumption with evidence from the IT market. Vast majority of it works against your expectation. Further, something like the Internet would require vast majority working for that expectation.
"Think of this way, what Govt. created/helped-created intially was a local network and only after thousands of ISPs coming together, not because of incentives from Govt, but because of demand we have the Internet as we know now."
It was actually a combo of military needing survivable, distributed comms with universities needing to collaborate with groups that were basically self-less and highly cooperative at the time. There were private parties trying to do their thing with their self interests even at that time. It was called OSI and circuit-based lines. One failed entirely, the other isn't what Internet was built on, and itself diminished over time in favor of faster, packet-switched lines. Even in ideal environment the incentives of businesses killed their opportunity while incentives of groups not motivated by profit led to Internet.
"Facebook, Slack, HTML, IRC != Internet. Question"
They make up vast majority of Internet traffic along with Netflix and Google. That makes them the Internet experience for most people. A lot of the rest is walled garden apps on mobile. Sites and services purely building on Internet technology, like IRC networks or FTP servers, are barely used because private parties rarely invest in them. It's simply too easy to escape lock-in that way. We can't throw out how 99% of people and products use the Internet when discussing Internet regulations or issues.
"I am not aware of any IP level walled-garden. "
You should look up ISP's like Comcast policies on web servers or SMTP ports. Stuff exists even at that level to serve the monetary interests of private market. Most of the walled gardens are built on top of the Internet protocols with ecosystem effect meaning you have to work within them to reach users they hit with First Mover advantage in new markets.
No, the free market crowd would recognize the cost of poor security for what it is, an externality. That fits into basic economic theory as something that the market won't naturally correct. No one will demand security if they're not the ones suffering from the lack of it.
Governments need to figure out some way to price in the externality. A good for instance would be to allow companies that don't take reasonable security measures to be held accountable for all damages caused, not just the portion attributable to their negligence. If Dyn had grounds to sue any device maker who, say, has a default password that isn't required to be changed during initialization before the device connects to the internet, then it would start to change things.
After enough of the fly-by-night device makers are hit with large judgments, it will start to become common practice to put every new device through security audits before introducing them into the market. Those reviews and the followup development will take time and cost money which will add to the final cost of the device, but make them safer.
Then companies can balance the cost of adding a secure enclave and a Grsec kernel (just an example) to their smart coffee maker against having to recall all of their infected products from the market when a botnet takes over them.
Besides that stick, I would throw a couple of carrots in there, too, like the companies being able to brag that their products are A+ security rated, etc, in their promotional materials and on their packages.
In short, I think regulations will prevent more damage than post-hoc legal retribution.
Time has proven that wrong so far. We got a lot of highly-secure products after DOD's Computer Security Initiative giving clear guidance plus financial incentive. DO-178B and other safety-critical markets are cranking out lots of them on safety side. So is segment of smartcard industry focused on high-security.
Regulation works so long as it has effective standards, they're clear, evaluated against product, and must be followed to sell the product. As in TCSEC era and DO-178B, reusable components for common cases show up to reduce the evaluation cost or risk. Open-source security would likely get a boost, too, as companies sponsoring it would sponsor certifiable versions with the higher QA.
Just cause it worked for the DOD doesn't mean it'll work everywhere else.
The constraints of DoD CSI, DO-178B, and the smart card industry focus are all embodied in regulations, which precede legal retribution.
If a company busts the regs, it can be sued. But the first line of defense is that companies are required to do it right - by the regulations.
I agree regulation needs clear definition and followup to be effective. I continue to regard regulation as a better mitigator of damage than post-hoc penalties.
Regulation is about preventing a mess. Litigation is about cleaning it up. I'd rather not have the mess to begin with.
That's exactly it. Although, I did propose possibility in this thread of defining regulations that aren't immediately applied but apply in court after harm is alleged. The reason being evaluation costs and time can be a big problem, esp for startups. This lets them simply follow guidelines with evidence produced during development & they only pay the cost if they screw up. The cost goes up with level of deviation and harm it caused.
There could be an interesting market for Apple clocks and Apple thermostats, but to increase the likelihood of something like that becoming popular (vs just using the easy Wi-Fi route), wouldn't it taken an unlikely push like that?
It will be a long time before manufacturers decide whether or not to put everything online, I think.
I say that sarcastically, but it seems to be where the world goes.
It is designed around local low bound (9600 bps) network where you can connect KNX devices (thermostats, actuators, sensors etc) or gateways/routers to other networks.
Only problem it has is that the communication is not encrypted, but being local and isolated, it is not a very big concern.
Every other home/building automation systems worked like this recently until some marketing geniuses came up with the IoT campaign.
Although I agree, what if one the devices that they communicate locally is connected to the Internet? Then it becomes just another level of indirection...
Too simplistic. If devices talk then there will be a way to listen and scale that talking/listening.