back

by zorked·9y ago·view on hn ↗
Calling for government regulation of devices is all fun and games until the government comes along and mandates closed source, irreplaceable firmware like the FCC did with Wifi access points.
4 comments
These problems need to be fixed soon or government regulation will come. I think the government would be reluctant to regulate unless it seems like an emergency. If larger attacks happen then the public will call for regulation and politicians will fall over each other to do it. There will be intended and unintended consequences.

He best way to prevent regulation is to eliminate the perceived need. If another attack hits, especially larger and more costly the one last week, people will start getting outraged. Those businesses who lost money might even start lobbying.

I'm not hopeful at this point as I don't even get the feeling that most people have taken the time to understand what happened last week. I see almost mantras people repeat out there outlining mitigation that, white important generally, would not have helped mirigste the attack last Frieay. The solutions offered frequently involve big lag times even if somehow set into motion immediately.

It may be necessary to make some hard trade offs to show some real progress. When people don't freely make hard choices, the government will step in. That would be a preventable tragedy. I don't have much hope at this point.

Good regulation isn't impossible. For example, mandating a unique admin password for each IoT device would go a long way to helping prevent this kind of fiasco.
How would a unique admin password help in cases where there's a backdoor accessed via an open port? A lot of the devices used last Friday had port 23 open. The password used in the backdoor was compeletely separate from the device admin password.

Your advice is good but it wouldn't have helped last Friday.

Unless it doesn't.

The EU version of that WiFi regulation also has a clause that while the default firmware for the router can't be allowed to be used for such purposes, users should always be able to install their own firmware.

Government regulation can be done effectively.

Which, of course, will result in a worse security posture. Interesting technical ideas can be found in the actual research being done on embedded device security out there. This comes to mind, for example: https://lwn.net/Articles/568943/