I'm almost certain that an excise tax on IoT devices proportional to how much damage they can do, combined with giving white hats legal immunity to hack devices as well as being paid a part of the device-tax, will be both more effective and cheaper than having politicians write detailed laws on software security.
If a company wants to drill into the ground looking for oil, and we know that this company can't pay the bill if things go wrong, we force them to pay an insurance premium/excise tax that covers the potential cleanup work. Of course we should do the same for devices that can be weaponized in this manner.
For example: a tax of 1 cent/mbit/s of network throughput, where 10% goes to administration costs, and 90% is paid out to white hats who are able to penetrate the device and display a "defective device; return to <local device-drop-off office>" message on the screen.
Proportional to how much damage they can do doesn't seem like a possible/reasonable measure. Should every car manufacturer now be responsible for insuring the cost of every car on the road causing a synchronized collision around the world? Should airplane manufacturers have to be insured for every airplane being in the sky, full of VIPs, and dropping onto the X most expensive buildings on earth, also full of prized possessions and more VIPs?
About giving white hats legal immunity to hack devices and be paid. How do you determine who is a white hat? Why wouldn't every black hat attempt to play the part of a white hat, gaining free range to play around with a system without any legal concerns. And if they find a crippling vulnerability, being able to sell it in a black market / partner with other black hats, and pretend they found nothing?
Those of us that worked in regulated industries (health, nuclear, etc.) had to do that for a long time now, at least based on my experience in Germany.
If your system has the potential to bring down the entire airfleet you sold, yes, you're on the hook for that event. Try building systems that are resilient in the face of failure, make that case to the insurer, premiums will go down.
I'm tired of the argument "well, we can break A LOT of shit in one go, so we shouldn't be held liable for our sloppiness". It's "too big to fail" in disguise.
http://www.theecologist.org/blogs_and_comments/commentators/...
So yes, air plane manufacturers might have insurance to cover them for all of their planes being down, but it's probably limited to the first-order damages of all of the planes being down, rather than the potential extra due to the fact they are all down at the same time.
e.g. If I own a mail-order business and I ship my stuff via air (with no contracts in place etc.), and suddenly no air planes can fly, so my business folds, I probably can't sue the air plane manufacturers.
In a similar way, the individual 'damages' that are attributed in a DDOS attack are due to the coordinated nature, rather than each device doing actual harm/damage.
"It's hard to do things right" is not an excuse for not doing them right.
I don't see why self-driving cars shouldn't be required to be insured either.
In this case, we might say that the manufacturer has a much stronger responsibility to keep their devices under control than in the case of, say, a typical PC where the user assumes more of that responsibility. The less freedom you give your users, the more power you reserve for yourself. That power should come with corresponding responsibilities.
For example:
- Mandatory security auditing of all pre-installed software
- Mandatory security updates for X years
- Mandatory insurance for damages caused by vulnerabilities in your products
Allow some of these requirements to be met by reusing previously audited and/or independently maintained software, giving manufacturers an incentive to stick with well-tested standard components. Waive some or all of the requirements if the device is allowed to be used as a general-purpose computer and/or all the software is freely available.
Best case scenario: we get routers and TVs labeled "Red Hat Embedded Linux inside: security updates guaranteed for 10 years."
As long as the industry is allowed to come to these SLA-like stamps on their own, on a per product basis, without government regulation breathing down their neck, this is exactly the way to go. IoT is so wide, there is no such thing as a "one size fits all". Any talk about across the board rules stinks of missing this obvious reality.
Nowadays, it's cheaper to stick a generic ARM SoC in your product and install a LAMP stack on it. It's also easier to find cheap developers that way. My router is just a bunch of CGI scripts running on an outdated Linux distro.
More likely fatal, or at least very costly.
To expand: there was the recent[0] attack on Dallas' tornado alarm. Imagine that was a disabling attack ahead of a tornado instead.
[0]: https://www.theregister.co.uk/2017/04/13/dtmf_replay_phreake...
What does "type of computer" mean? And why would this need regulation (are some "types of computers" less secure than others)?