- There are so many different kinds of devices and different hardware
- Vendors want to maximize profits like everyone else, which entails making new devices all the time, and ending support on the last model fairly quickly (typically within two years,) but consumers regularly keep their devices for more than two years.
- Hardware vendors historically were not software vendors. For many IoT makers, this is their first real foray into software. The mistakes being made are amateurish, at a level that we saw on PCs in the mid-90s.
- Although there are some IoT standards, they're mostly concerned with communications, not the operating system. It feels like we're still 5+ years off from something as basic as automatic updates being a given (even just notifying users that an update is available and allowing them to easily install it is a challenge currently.)
Two things that are really bothersome:
- A huge number of IoT devices don't need the 'I'. They are perfectly capable of serving their purpose without an Internet connection (e.g. over Bluetooth,) but a huge attack surface is added to make you able to configure the device via a central website, or simply to monetize usage data.
- It is futile to trust each vendor to have the security expertise to lock down every device. An "IoT operating system" would be highly desirable, but there is nothing anywhere near real world implementation, and given the heterogeneous of hardware components it doesn't seem likely something non-Linux-based will come along.
Brickerbot is hostile and aggressive and shouldn't be necessary, but maybe it is. That's beside the point, though: Nobody has to be given permission to brick insecure IoT devices. Vendors don't feel it where it hurts (the bottom line,) and consumers increasingly just don't care (studies show people have grown accustomed to security incidents -- "it happens to everyone and everything; replace it and move on, there's nothing you can do")
Hacks made Microsoft shape up in the 90s and early 2000s, but Windows has only become actually secure since after Vista. Maybe just don't buy IoT devices for another 5-10 years, or at least put them on a separate vlan.
There are a bunch of groups trying to spread the word, but it doesn't seem many vendors are listening (or if they are, they don't have the capability to really secure their devices.) We've had some success with Securing Smart Cities working with local and state governments, and trying to address some of these issues before hilariously insecure IoT hardware becomes ubiquitous in cities/related to critical infrastructure: http://securingsmartcities.org/
It's hard to see how it's not going to get much, much worse before it gets better.