US senators planning bill to ‘secure’ the Internet of Things but users are a weak link, say experts

A bipartisan group of U.S. senators plans to introduce legislation on Tuesday aiming to address vulnerabilities in internet of things (IoT) devices, according to a report from Reuters in San Fransisco. Security experts have long warned that this poses a threat to global cyber security.

The new bill would require vendors that provide internet-connected equipment to the U.S. government to ensure their products are patchable and conform to industry security standards.

The proposed legislation aims to prohibit the production of IoT devices if they can’t be patched or have their password changed, says Jeremy Cowan. The bill also calls for federal agencies to have the freedom to purchase non-compliant IoT devices should this legislation pass, if they get approval from the US Office of Management and Budget.

Commenting on the news, Travis Smith, principal security engineer at security specialists Tripwire said: “As it stands now, the S in ‘IoT’ stands for security! This bill will help to resolve some of the known issues plaguing so many IoT devices being hacked on a daily basis. There are two issues I see with this bill which won’t help in the overall security of these types of devices. When left up to the user, changing passwords and installing patches is not a priority. The priority instead is getting the device to work so you can stream Netflix from your fridge or see your front porch from a beach.

IoT devices in three buckets

“I put IoT devices into three buckets when it comes to patching.  The best bucket to be in are devices which automatically detect new updates and install them without any user involvement. This is the strategy which should be strived for amongst all IoT vendors. The next is optional patches, which is what this bill will most likely mandate. Two issues with optional patches are first getting the user to know about the patch, then getting them to actually install the patch. Both of these tasks are notoriously difficult for your average user. Finally, there are the devices which do not receive any patches; intentionally or not.

“Along the same lines as having users install patches is getting them to change their passwords,” said Smith. “The reason Mirai was so successful was not because users could not change their password, but because they chose not to when installing the device. I would urge this bill to add that devices should force the user to change the default password, but that the default password should be unique to each device as well. Even something as simple as using a MAC address, while not secure, is one step better than using the default admin/admin credentials we have become accustomed to.”

“For this bill to be successful, there needs to be incentives for vendors to get their devices to a secure state. Releasing a device which is free from security bugs is time-consuming and costly. With many of these devices being a commodity, delaying the time to market or charging a higher cost may not fit their current business model,” he concluded.

Mike Bell

In addition to this Mike Bell, EVP Devices & IoT at Canonical commented: “This is an important step in ensuring better security standards for devices. Nearly half of IoT professionals (45%) surveyed by Canonical highlighted better device security as their most immediate IoT challenge, and the ability to patch devices remotely is crucial in ensuring security holes can be filled quickly, safely and painlessly.

“That’s why Canonical has invested in ensuring that our IoT operating system, Ubuntu Core, has built-in remote patching capabilities. And, with the U.S. government’s IoT spending already reaching nearly $9 billion in 2015, any new standards set by Congress will be sure to impact enterprise and consumer vendors,” said Bell.

Comment on this article below or via Twitter: @IoTNow OR @jcIoTnow

RECENT ARTICLES

SandboxAQ’s AQtive Guard deployed by SoftBank for cryptographic security

Posted on: April 16, 2024

SandboxAQ have announced the deployment of its AQtive Guard cryptography management platform by the Advanced Research Group of SoftBank. This followed testing of AQtive Guard’s abilities to discover cryptographic and certificate-based vulnerabilities to AI-based and quantum computer-based cyber attacks against IT systems, including networks, end-points and applications.

Read more

VOZIQ AI sets AI retention strategy for Hawx

Posted on: April 15, 2024

VOZIQ AI recently concluded the executive review meeting with Hawx’s leadership team, where VOZIQ AI’s chief data scientist, Vasudeva Akula, rolled out a 365-day roadmap for proactive customer experience management, proactive renewals and loyalty management, using AI driven insights for each customer.

Read more
FEATURED IoT STORIES

What is IoT? A Beginner’s Guide

Posted on: April 5, 2023

What is IoT? IoT, or the Internet of Things, refers to the connection of everyday objects, or “things,” to the internet, allowing them to collect, transmit, and share data. This interconnected network of devices transforms previously “dumb” objects, such as toasters or security cameras, into smart devices that can interact with each other and their

Read more

The IoT Adoption Boom – Everything You Need to Know

Posted on: September 28, 2022

In an age when we seem to go through technology boom after technology boom, it’s hard to imagine one sticking out. However, IoT adoption, or the Internet of Things adoption, is leading the charge to dominate the next decade’s discussion around business IT. Below, we’ll discuss the current boom, what’s driving it, where it’s going,

Read more

9 IoT applications that will change everything

Posted on: September 1, 2021

Whether you are a future-minded CEO, tech-driven CEO or IT leader, you’ve come across the term IoT before. It’s often used alongside superlatives regarding how it will revolutionize the way you work, play, and live. But is it just another buzzword, or is it the as-promised technological holy grail? The truth is that Internet of

Read more

Which IoT Platform 2021? IoT Now Enterprise Buyers’ Guide

Posted on: August 30, 2021

There are several different parts in a complete IoT solution, all of which must work together to get the result needed, write IoT Now Enterprise Buyers’ Guide – Which IoT Platform 2021? authors Robin Duke-Woolley, the CEO and Bill Ingle, a senior analyst, at Beecham Research. Figure 1 shows these parts and, although not all

Read more

CAT-M1 vs NB-IoT – examining the real differences

Posted on: June 21, 2021

As industry players look to provide the next generation of IoT connectivity, two different standards have emerged under release 13 of 3GPP – CAT-M1 and NB-IoT.

Read more

IoT and home automation: What does the future hold?

Posted on: June 10, 2020

Once a dream, home automation using iot is slowly but steadily becoming a part of daily lives around the world. In fact, it is believed that the global market for smart home automation will reach $40 billion by 2020.

Read more

5 challenges still facing the Internet of Things

Posted on: June 3, 2020

The Internet of Things (IoT) has quickly become a huge part of how people live, communicate and do business. All around the world, web-enabled devices are turning our world into a more switched-on place to live.

Read more