United Kingdom to introduce security labelling on connected devices
mender.io
mender.io
An individual consumer who purchases a poorly protected network device is unlikely to suffer any meaningful individual harm, like having their computer ransomwared.
Rather, it makes things like botnets possible that can be used for all sorts of things, e.g. DoS attacks against a third party.
So why should a consumer do anything but ignore the label? It's the rational choice if the less-secure product is cheaper.
If we want security standards, they need to be legislated democratically and applied to all devices -- not left up to consumer choice.
Now whether a legislature is capable of doing that effectively is certainly an open question. But I'm afraid labeling may be no more than an ineffective band-aid.
It opens the door to liability for companies who purchase insecure network devices. If your peers are buying good hardware while you're buying self-identifying garbage, someone harmed by a botnet running on your metal has a better argument, now, that you were knowingly reckless.
That's a huge shift, and about as far from "moot" as you can get.
It is reasonable to say that, even if companies are discouraged from purchasing insecure devices, that won't necessarily deter consumers purchasing insecure devices for their households. The threat from devices in households is perhaps even greater than in businesses, if the number of households in question is great enough.
If every piece of hardware has the same label, that argument dries up and blows away.
If some piece of hardware doesn't have the label and later gets owned, the manufacturer will be held accountable. It would have to be, or else this is toothless. Since no manufacturer can predict which vulnerabilities may be discovered, and since legal teams are a cowardly and superstitious lot, every manufacturer will put the label on now to avoid any potential problems later.
It's likely that if you literally fly out, buy them, pack them in a suitcase and fly home they'd make it, but if you try to buy a crate of obviously non-compliant Product X and it arrives at a port there's a reasonable chance somebody says "This Product X is non-compliant, so, why the hell is that here?" and you're not going to receive it.
You might think well, surely they don't look in most crates. And they don't. They don't look in the forty identical crates of compliant seatbelts going to Ford, because why would Ford be like "Hey, let's order 39 crates of complaint ones, but order 40 crates with #8 non-compliant to kill a few customers as a joke" ?
They're going to look in your crate because you never ordered any crates of seatbelts before, and "Bo Yang Belts" never sent anybody in your country a crate of anything before. Because their products aren't compliant to anybody's standards and so you're their first foreign sale.
But actually you may never even get to buy them. The huge first world economies like the EU and US order such enormous volumes of stuff and require compliance to their standards that it just often doesn't make sense to make Product A for them and then also Product B that's much worse but a bit cheaper for domestic use. I wouldn't like to guess if seatbelts are such a product.
What's the point is holding companies which purchase products liable for the quality of those products? That's a step removed for literally zero benefit I can see.
Just hold the manufacturers liable directly. In other words: standards, not labels.
To use a car analogy if your car gets into an accident because the break pads should have been replaced 10,000 miles ago that is your fault. If it is because the break pads disintegrate if they get wet that is the manufacturer's fault.
These aren't cars however, but it does bring to mind a hypothetical consistent set of standards involving patches. So if say the product was perfectly fine at launch on 32-bit platforms but it has a bug when run on 64-bit platforms it would become the user's problem.
It obviously wouldn't be a very good system, it isn't realistic in its expectations nor easy to judge or administer with all of the nuances and fine details of knowledge.
I know I will.
The number of stories I've read of poorly secured connected devices aimed at children. Stories of flaws so basic that it would be trivially easy for an attacker to get the child's location and send them messages posing as a parent.
Individual consumers will be very concerned about devices that could potentially allow their child to be lured to some random location and attacked.
I get where you are coming from, and forgive me for going all libertarian but... I have less than zero trust in governments (especially mine in the UK). They don't understand tech. They don't want or try to understand tech. They have zero interest in personal freedom or autonomy.
If the UK government did this, I'd go out of my way to find a "non secure" phone as anything they licensed would just have massive insecure backdoors and probably wouldn't actually work as a phone...
Sorry for the rant. I'd honestly like more security in my devices...
But if you want security standards, and bob does not, why should bob be forced to want them?
“I refuse to change away from my Linux2 busybox/php based home automation devices. https gives you autism!”
(Maybe we can maintain “herd immunity” by abandoning ipv4, and moving the “healthy herd” all over to an ipv6 only internet?)
The botnet that infects Bob's equipment will harm others. The same way his car might.
I suspect the long term answer here might look a lot like the auto industry. You won’t be allowed to sell network-connecting devices that don’t meet certain minimum security standards. Manufacturers will need to commit to a minimum security update period (like car manufactures need to commit to spare parts availability - for at least 10 years after the sale here in .au), and purchasers will will be required to accept responsibility for device’s operation, some of which will be mitigateable by insuring against it, but irresponsible use will not be covered by insurance and become the owner’s responsibility. (Admin while Under Influence? Speed limits on pushing patches?)
I don’t see a clear path to that kind of regulatory control over $15 devices sourced directly out of China by every vanishing retailers/manufactures though, and there’s a whole raft of genuinely useful use cases for inexpensive net connected hardware that’d be impossible or illegal if the expense of the sort of regulatory burden place of car drivers was imposed on people with smart powerpoints or dash cams...
I don't think mandatory security requirements for webcams is going to do much about that...
Instead, we should be thinking about how packets can be source and destination signed, and how unsigned packets can be dropped in the network rather than clogging up their destination.
A more important piece of legislation would be to require governmental security agencies to inform companies of the security flaws in their products and to require the companies to fix them. Organisations like the NSA stockpile security flaws in secret in order to exploit the flaws for their own ends.
The WannaCry malware caused worldwide economic damage and was a direct result of the NSA losing control of its EternalBlue exploit. Had the NSA reported the flaw to Microsoft the problem could have been fixed before it ever became a problem:
https://en.wikipedia.org/wiki/WannaCry_ransomware_attack
https://theintercept.com/2017/05/16/the-real-roots-of-the-wo...
It's unacceptable that these organisations are permitted to act like cowboys with our common infrastructure. These are not messes I want to spend my days cleaning up.
Look at anti-virus software. While some of it is legit, a lot of it is garbage that doesn't do anything. But people will happily buy (or subscribe) because it promises to improve security. And fear sells.
I don't know specifically what the label is going to look like. But let's suppose that the government set 5 years of security updates as the minimum standard. And suppose that if a company only promised to provide 3 years, their product would have to bear a label saying, "WARNING: Does not meet minimum required government computer security standards. May lack software updates that protect from hacking." I think that would discourage a lot of people from buying it.
And conversely, if meeting certain security standards allowed the manufacturer to label their product as officially scoring "Very Good" or "Excellent", they'd want to put that on their label. Manufacturers always like to maximize the number of good-sounding things on the box. To the point that they'll invent useless bullet items to fill the space if they can't think of anything else to say.
* A commitment and ability to update any critical security issues for a specified amount of time
* Standardised mechanisms for reporting critical updates to users which are not used for marketing
* A basic checklist of best practice for internal self-audit (SQL injection, plaintext data, enumeration attacks)
A low bar, but still far better than what we've currently got. (External audits are probably silver tier?)
But I can also see how that could be abused by bad actors so I guess it would be a tricky part of the policy to do correctly.
- 2-factor auth support
- federated login support (i.e. login with Google/Facebook/etc buttons)
- some sort of indication of encryption in-flight and at-rest, and who handles the keys (e.g. is there a per-user key that tech support can't even access without user grant, or is there a single hard-codes AES key in the APK etc that everyone knows)
I think this is a massive ask/knowledge expectation for the average person. A simple warning label about changing the device password from the default would be a major step in the right direction for consumers.
- All consumer internet-connected device passwords must be unique and not resettable to any universal factory setting
- Manufacturers of consumer IoT devices must provide a public point of contact so anyone can report a vulnerability and it will be acted on in a timely manner
- Manufacturers of consumer IoT devices must explicitly state the minimum length of time for which the device will receive security updates at the point of sale, either in store or online
How do they expect to enforce these requirements on the manufacture of the IoT crap sold by the vendor “Best Security Happiness Store” on AliBaba, and the unnamed (or outright counterfeit named) Chinese manufacturer they bought it from?
And conversely, they could obviously easily apply this to the UK based Raspberry Pi foundation, but who’s responsible for enforcing the “no way to reset to a known factory password” for the pi:raspberry login from a stock Rasbian install? (Or do we just hand wave that away and say “that’s not a consumer device, even though we’ve shipped over 30 million of them!”?)
The trouble is, they (or at least, a good number of them) aren't doing so at the moment. This will get them to at least address the easy stuff.
A couple of car analogies might be, that car manufacturers are required to have cars repairable for x years, and that recalls to repair dangerous defects are mandatory. In the case of IOT, the recalls could just be mandatory updates.
For example its an obvious public and environmental benefit to require that all phones have a user replaceable battery but until recently they almost all did and now it's too late because every phone maker would lobby against it.
I see another aspect of this. Societies have allowed tech companies to run unregulated in a trader-off between safety and technological advance.
Medical equipment, cars or planes are examples were regulations were put in place as safety failures have more dangerous consequences.
As devices are more ubiquitous and the economy and lives depend more on them, further regulation will be pushed forward.
> and now it's too late because every phone maker would lobby against it.
I agree that will take political will to regulate the tech industry. But, in the same way that phone manufacturers do not want replaceable batteries the rest of industries will see their costs reduced by such a regulation. So, there is also opposing forces that want big tech to play nicer with the rest of the industry ecosystem. And, in democratic countries, population will also push for change as their lives are disrupted by the lack of regulation.
I would like a warning label if the device requires an internet connection for normal operation or features that don't really need it, so I can decide not to buy it if the requirement is unreasonable.
https://www.gov.uk/search/policy-papers-and-consultations?or...
https://news.ycombinator.com/item?id=22343786
Part of the idea is that people will modify their behavior when there's visible indication they're conducting a risky activity.
https://web.archive.org/web/20190212185530/https://trustable... (edit: linking via archive.org as the site appears to be redirecting at least some clicks to scam sites)
The axes are interesting and a good starting point. From their site:
* Privacy & Data Practices: Is it designed using state of the art data practices, and respectful of user rights?
* Transparency: Is it made clear to users what the device does and how data might be used?
* Security: Is it designed and built using state of the art security practices and safeguards?
* Stability: How robust is the device and how long of a life cycle can a consumer reasonably expect?
* Openness: How open are both the device and the manufacturer‘s processes? Is open data used or generated?
How did that happen? I have JavaScript disabled and an adblocker installed...
Edit: My browser's history:
* https://trustabletech.org/about/#
* http://www.wosemdesy.site/[...loads of crap here...]
* http://competition5783.primeluck26.live/*******/[...loads of crap here...]
Fun stuff. Gives me tons of confidence TrustableTech can be trusted and certifying device security globally. Trusted Technology Mark? To me this will mean "unsafe".
> https://www.etsi.org/deliver/etsi_en/303600_303699/303645/02...
About 30 pages of broad points. Judicious use of "where applicable".
Still, it's a start.
- There is no non-free firmware or other software on the device.
- The consumer is provided full source code to the software and can effectively replace the preinstalled version with a version they have compiled themselves.
- The manufacturer provides updated versions of any software or firmware (again, including full source code) to patch any discovered security vulnerability for the expected life of the device: at least three years for most devices, but perhaps as long as 30 to 60 years for some devices. This lifetime is disclosed.
- The device does not transmit any personally identifiable information back to the manufacturer in its default configuration; for example, audio recordings, power usage measurements, accelerometer readings, temperature readings, or customer login names or account numbers.
Unfortunately, I don't think such requirements are viable in the current political situation. That doesn't change the fact that any device that fails to comply with them introduces a serious security vulnerability: there is no way for the users to defend themselves against malicious actors who penetrate the manufacturer. The Dieselgate scandal and the Huawei prohibition are only the mildest taste of what we are in for.
Of course it is not practical for every person to audit the source code of the firmware for every TV remote control and power brick they use, but it is possible for people to organize consumer watchdog agencies that do perform such audits.
https://news.ycombinator.com/item?id=22343786
It seems like if we want to solve this problem we need to somehow modify users' behavior by making them aware that indiscriminate browsing is a risk.
I presume the idea is that your Apple Foozle is safe, and so is this Famous Brand Foozle and this Obviously Rebadged Generic Foozle that's half the price of the Apple product, but the foozle your mate got from the geezer who used to get him pirate DVDs doesn't have the sticker. No surprise when your mate gets ransomware a few months later. They saw him coming.
def IsDeviceSecureEnoughForUKGovernment():
if manufacturer=='Huawei':
return "Not Secure. Use sparingly"
return "Certified Secure"