Security

Bruce Schneier: You want real IoT security? Have Uncle Sam start putting boots to asses

Infosec's cool uncle says to hell with the carrot


Any sort of lasting security standard in IoT devices may only happen if governments start doling out stiff penalties.

So said author and computer security guru Bruce Schneier, who argued during a panel discussion at the Aspen Cyber Summit this week that without regulation, there is little hope the companies hooking their products up to the internet will implement proper security protections.

"Looking at every other industry, we don't get security unless it is done by the government," Schneier said.

Schneier warns of 'perfect storm': Tech is becoming autonomous, and security is garbage

READ MORE

"I challenge you to find an industry in the last 100 years that has improved security without being told [to do so] by the government."

Schneier went on to point out that, as it stands, companies have little reason to implement safeguards into their products, while consumers aren't interested in reading up about appliance vendors' security policies.

"I don't think it is going to be the market," Schneier argued. "I don't think people are going to say I'm going to choose my refrigerator based on the number of unwanted features that are in the device."

Schneier is not alone in his assessment either. Fellow panellist Johnson & Johnson CISO Marene Allison noted that manufacturers have nothing akin to a bill of materials for their IP stacks, so even if customers want to know how their products and data are secured, they're left in the dark.

"Most of the stuff out there, even as a security professional, I have to ask myself, what do they mean?" Allison said.

That isn't to say that this is simply a matter of manufacturers being careless. Even if vendors want to do right by data security, a number of logistical hurdles will arise both short and long term.

Allison and Schneier agreed that simply trying to port over the data security policies and practices from the IT sector won't work, thanks to the dramatically different time scales that both industrial and consumer IoT appliances tend to have.

"Manufacturers do not change all the IT out every five years," Allison noted. "You are looking at a factory having a 25- to 45-year lifespan."

Support will also be an issue for IoT appliances, many of which go decades between replacement.

"The lifespan for consumer goods is much more than our phones and computers, this is a very different way of maintaining lifecycle," Schneier said.

"We have no way of maintaining consumer software for 40 years."

Ultimately, addressing the IoT security question may need to be spearheaded by the government, but, as the panelists noted, any long-term solution will require a shift in culture and perception from manufacturers, retailers and consumers. ®

Send us news
67 Comments

US government excoriates Microsoft for 'avoidable errors' but keeps paying for its products

In what other sphere does a bad supplier not feel pain for its foulups?

US legislators propose American Privacy Rights Act - and it looks quite good

After two decades of calls for national protections, something may actually happen

Rust developers at Google are twice as productive as C++ teams

Code shines up nicely in production, says Chocolate Factory's Bergstrom

In-app browsers are still a privacy, security, and choice problem

Regulators reminded that longstanding concerns haven't been addressed

Academics probe Apple's privacy settings and get lost and confused

Just disabling Siri requires visits to five submenus

Google will delete data collected from 'private' browsing

Declares victory in settlement of class action lawsuit, but individual claims remain possible

Majority of Americans now use ad blockers

We're dreaming of a white list, because we're just like the ones you used to know

Microsoft slammed for lax security that led to China's cyber-raid on Exchange Online

CISA calls for 'fundamental, security-focused reforms' to happen ASAP, delaying work on other software

Lawsuit claims Meta hobbled Facebook Watch to help Netflix

Advertiser antitrust lawsuit says claimed deal with Netflix is anticompetitive

Row breaks out over true severity of two DNSSEC flaws

Some of us would be happy being rated 7.5 out of 10, just sayin'

Amazon finishes pumping $4B into AI darling Anthropic

Adds $2.75B to the ML sweepstakes ante and is counting on Claude

Head of Israeli cyber spy unit exposed ... by his own privacy mistake

Plus: Another local government hobbled by ransomware; Huge rise in infostealing malware; and critical vulns