Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

But IMO this isn't a "safety" issue with the devices themselves that could hurt the users unintentionally, this is a 3rd party "weaponizing" the system for their own use.

I'm struggling think of a good analogy, but it seems more like suing Ford because thieves can easily steal their cars for use in robberies.

In essence, the device is being used by an unauthorized 3rd party to harm a 4th party. The device owner in some cases is never harmed or even inconvenienced, and neither is the manufacturer.

It's a shitty situation, and I don't personally know where the line should be drawn, but IMO it should be drawn clearly.



i'd compare it to freon and freon using devices which had to be properly utilized or the ozone layer got hurt, only now substitute freon for 'product with ability to connect to the internet that doesn't get security updates anymore'. such devices should be disconnected from any non-air-gapped network or they're a considerable risk for their environment (the internet).


The "EPA" is actually a perfect "analogy".

We need an IPA (perhaps a different name...). We need someone that will set "standards" for a minimum baseline of "security" to ensure the health of the internet, and dole out fines based on violations.

However they need to be VERY careful. With something like freon it's a physical "thing" that can be regulated. We don't want to regulate "ideas" or even code, that to me seems like a very dangerous thing.

But you are right, we need something that will protect the "health of the internet" like we protect the health of our environment.


How do you add any regulation without regulating the code? code is our environment.


I meant more that I don't want it to be a crime to write a TCP stream handler without SSL. Or to need a license to write crypto code.

To me it gets dangerously close to regulating ideas.

I'd want to it more based in consequences. If your product or code is used in an attack, you get fined. No need to dictate the code or software solutions allowed.


Yeah comparing this to toy safety is quite a leap. Actual internet connected toys? Sure. But what I see is a network gateway device in a slew of such devices in a still nascent industry which really hasn't figured out how to even create fully secure network protocols yet, much less hardware. This will have a chilling effect on innovation in the field more than it will improve security in the large.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: