TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

We're Surrounded by Billions of Internet-Connected Devices. Can We Trust Them?

78 pointsby tdrndover 5 years ago

14 comments

semiotagonalover 5 years ago
&gt; But Kennedy&#x27;s biggest concern at the moment is in the area of automotive safety<p>No doubt. I was pricing out a Mercedes online, and looking through the summary one of the standard features was &quot;over-the-air updates&quot;. That is the last thing in the world I want. An expensive car shouldn&#x27;t be acting like an Android phone. It shouldn&#x27;t be connected to the internet at all.<p>If it&#x27;s updating anything other than the entertainment system, then they&#x27;re <i>completely</i> nuts. Get the internet out of my car, I already have a phone for that.
评论 #21537814 未加载
评论 #21539055 未加载
评论 #21538065 未加载
评论 #21538949 未加载
评论 #21537022 未加载
评论 #21538601 未加载
评论 #21545743 未加载
评论 #21539238 未加载
pjc50over 5 years ago
I don&#x27;t think they can be trusted to be either secure or reliable or even supported. Any of them could be remotely disabled at any time as the parent company goes out of business.<p>On the other hand, at the moment they&#x27;re mostly in frivolous devices. As they become ubiquitous this is going to demand EU-level intervention, just like the existing WEEE directive against lockout chips on printer cartridges.<p>Americans will be stuck with <i>caveat emptor</i> levels of consumer protection.
评论 #21536649 未加载
评论 #21539273 未加载
CapitalistCartrover 5 years ago
IOT devices use standard, commonly available boards and chips, which are meant for widely varied applications, so offer wifi&#x2F;Internet connectivity easily. So companies can add that &quot;feature&quot; painlessly by applying a snippet of (usually OSS) code. And collecting all the customer data they can is a bonus. No penalty of zero security, major upside if they sell it.<p>This is dangerous to all of us, even if you don&#x27;t own any IOT devices.
评论 #21537223 未加载
_wlduover 5 years ago
Zero Trust. This is a basic network security tenet that was first introduced in 2010: <a href="https:&#x2F;&#x2F;www.darkreading.com&#x2F;attacks-breaches&#x2F;forrester-pushes-zero-trust-model-for-security&#x2F;d&#x2F;d-id&#x2F;1134373" rel="nofollow">https:&#x2F;&#x2F;www.darkreading.com&#x2F;attacks-breaches&#x2F;forrester-pushe...</a>
dsalzmanover 5 years ago
IOT. The S stands for security.
评论 #21538109 未加载
评论 #21542344 未加载
xyzzy_plughover 5 years ago
&gt; Can We Trust Them?<p>Of course not.
phs318uover 5 years ago
We need something like this:<p><a href="https:&#x2F;&#x2F;foundation.mozilla.org&#x2F;en&#x2F;privacynotincluded&#x2F;" rel="nofollow">https:&#x2F;&#x2F;foundation.mozilla.org&#x2F;en&#x2F;privacynotincluded&#x2F;</a><p>expanded to every type of IoT. Imagine a kind of mandatory labelling for any device with data-capture and&#x2F;or telemetry capabilities.
JohnFenover 5 years ago
I think the clear answer to this is &quot;no&quot; on a couple of different levels. I don&#x27;t think it&#x27;s safe to trust that the actual communications are properly secured, and I don&#x27;t think it&#x27;s safe to trust the companies that these devices report to.
forgingaheadover 5 years ago
No.<p>&#x2F;end thread
Havocover 5 years ago
Yeah the cheap IoT stuff is just wild. No passwords &#x2F; weak security is pretty much the norm
ubertakterover 5 years ago
No. Next question please.
ryeightsover 5 years ago
Betterridge&#x27;s law of headlines strikes again: <a href="https:&#x2F;&#x2F;en.m.wikipedia.org&#x2F;wiki&#x2F;Betteridge&#x27;s_law_of_headlines" rel="nofollow">https:&#x2F;&#x2F;en.m.wikipedia.org&#x2F;wiki&#x2F;Betteridge&#x27;s_law_of_headline...</a>
评论 #21537614 未加载
moonbugover 5 years ago
Betteridge.
stopadvertisingover 5 years ago
Every time I try to buy some device that is LAN only and doesn&#x27;t talk to the net, ever, I usually find zero options or few crappy, expensive choices. Why anyone would install a camera that then talks to some corporation&#x27;s cloud is beyond me, I have zero interest in that.
评论 #21536856 未加载
评论 #21538357 未加载