Experts to Congress: You must act on IoT security. Congress: Encourage industry to develop best practices, you say?

Schneier crap-storm warning falls on deaf ears

Congress provided a masterclass in selective hearing Wednesday when urged by experts to do something about the increasing risk posed by poor IoT security.

At a session of the House's Energy and Commerce Committee into last month's attack on DNS provider Dyn that caused widespread disruption to online services, several security experts highlighted the main problem as a lack of security standards and urged Congress to act. Their pleas were repeatedly rebuffed.

Chief security officer of Level 3, Dale Drew, warned [PDF] representatives that "the current lack of any security standards for IoT devices" was a big part of the problem, and said IoT manufacturers needed to "embrace and abide by additional security practices to prevent harm to users and the internet."

He argued that "there may be a role for the government to provide appropriate guidance."

Likewise, CEO of Virta Labs, Dr Kevin Fu, said [PDF] that "IoT security remains woefully inadequate, and the Dyn attack is a sign of worse pains to come." Fu took a stronger line on government intervention, arguing that it needs to actively support agencies that were developing solutions to IoT security issues, including looking at establishing "an independent, national embedded cybersecurity testing facility."

But it fell to security guru Bruce Schneier to argue outright [PDF] for legislation. "Like pollution, the only solution is to regulate," he stressed. "The government could impose minimum security standards on IoT manufacturers, forcing them to make their devices secure even though their customers don't care."

He continued: "They could impose liabilities on manufacturers, allowing companies like Dyn to sue them if their devices are used in DDoS attacks. The details would need to be carefully scoped, but either of these options would raise the cost of insecurity and give companies incentives to spend money making their devices secure."

Benign – but not for long

In order to stress the importance of the issue, Schneier noted that the DDoS attack on Dyn, as disruptive as it was, was still largely "benign."

"Some websites went offline for a while. No one was killed. No property was destroyed. But computers have permeated our lives. The Internet now affects the world in a direct physical manner. The Internet of Things is bringing computerization and connectivity to many tens of millions of devices worldwide. We are connecting cars, drones, medical devices, and home thermostats. What was once benign is now dangerous."

The calls for government intervention met a brick wall in the Republican-held House, however.

Michael Burgess (R-TX) stressed in his opening remarks that the answer to the security issues was in developing "best practices," and government's role was to elicit a "meaningful response from industry."

Bob Latta (R-OH) noted that there needed to be "IoT security guidelines to keep pace with rapidly evolving technologies," but stressed there was a "delicate balance between oversight and regulatory flexibility" and that it should fall on industry to develop best practices that would "not hinder innovation."

Even Democrats steered clear from suggesting that the government take a direct role in the situation. Anna Eshoo (D-CA) noted that the IoT security problem was a "global issue" and noted that "little more than a quarter" of the devices that were involved in the recent attacks were located in the US, while the products "most vulnerable" were based in China. The implication was obvious: what's the point in legislating when China is the real problem?

Despite the clear flags, Bruce Schneier remained determined to push the case for government to act. "The market really can't fix this," he argued. "The buyer and seller don't care," he stressed. "Government has to get involved. This is a market failure. This is not something the market can fix."

He proposed that the government should create a new agency to look into the issue, since even just his mobile phone crosses multiple government agencies' jurisdictions.

Keep Reading

Mobile World Congress to run this year's Barcelona event in June with 50,000 attendees. We're speechless

And the COVID-19 precaution? A negative test 72 hours before

Hard to believe but Congress just approved an IoT security law and it doesn't totally suck

Secure coding, identity management, patching, configuration controls, what madness is this?

United States Congress stormed by violent followers of defeated president, Biden win confirmation halted

Updated Images of evacuated and invaded offices, Senate PCs still left switched on shared online

Stop asking for Amazon, Google and Microsoft cloud with 'no justification': US Library of Congress told to drop its 'brand-name'-tastic RFP

Oracle wins protest after agency failed to get it kicked out for not being a reseller

After Trump, Congress, Supreme Court Justice hit out at tech giants' legal immunity, now FCC boss wants to stick his oar in, too

Pai says he wants to 'clarify' Section 230's 26 words even though he probably can't do anything about it

FCC boss pleads with Congress: Please stop me from auctioning off this spectrum for billions of dollars

In unusual turn of events, Ajit Pai warns he’ll do his job unless stopped

As the US maybe gets serious about coronavirus-tracking apps, Congress wakes up to the privacy risks

Just what will happen to all that tasty location and contact data?

Half a billion here, half a billion there – pretty soon you're talking real money: US Congress earmarks $425m for 2020 election security

Just another, oh, $1.675bn to go to defend systems, it is estimated

Biting the hand that feeds IT © 1998–2021