create account

Are Cybersecurity Labels on IoT Devices a Wasted Effort by mrosenquist

View this thread on: hive.blogpeakd.comecency.com
· @mrosenquist ·
$17.98
Are Cybersecurity Labels on IoT Devices a Wasted Effort
<html>
<iframe src="https://www.youtube.com/embed/Ohfip99riqo"></iframe>
<p>
<br/>The U.S. is exploring the idea to establish cybersecurity labels on IoT devices and software, in hopes it will both inform consumers of risks and motivate manufacturers to improve the security for the flood of new products entering the market.</p>
<p>Internet-of-Things (IoT) devices number in the billions, some estimates are as high as 46 billion, and continue to emerge at a quickening pace with consumers and across industrial uses. Yet they often are weak when it comes to being hacked, which creates growing risks to consumersโ€™ privacy, security, and even safety.</p>
<p>The U.S. has indicated a desire to adopt some kind of labeling and has kicked off discussions with manufacturers. The National Institute of Standards and Technology (NIST), within the U.S. Dept of Commerce, is leading the effort and is soliciting input from IoT manufacturers and the public.</p>
<p>Given the self-interest involved, I am somewhat skeptical of what the manufacturing industry will recommend or voluntarily implement when it comes to Cybersecurity Labels for IoT devices. The core problem is that the industry itself is not putting forth the effort to implement basic cybersecurity functionality into its product architecture and designs. This group is now being asked to develop a label standard to help consumers and I expect the results to be less than stellar.</p>
<p>On the upside, I do applaud the creative concept of security labeling as an out-of-the-box idea and involving the private sector, but this path has significant weaknesses when it comes to how the relevant content of the disclosures will be decided and the challenges for meaningful absorption by the consumer.</p>
<p>There are many efforts, by security, overseas governments, and academic organizations, which show promise but also have challenges.</p>
<p>The CyLabs team out of Carnegie Mellon University has developed a very comprehensive label, but I think it is far too complex for consumers to understand.</p>
<p><img src="https://cdn-images-1.medium.com/max/800/1*-5GudKx0n3foercXmBN4Ng.png"/></p>
<p>Symantec has developed a scaled-down version of what CyLabs proposes, but the data does not readily translate to something meaningful to the average consumer.</p>
<p><img src="https://cdn-images-1.medium.com/max/800/1*SOvh0gWxQa-hF8ACGV6loA.png"/></p>
<p>The city-state of Singapore strikes a balance between independent verification and self-reporting, but overall, it is overly simplistic to convey a meaningful risk picture.</p>
<p><img src="https://cdn-images-1.medium.com/max/800/1*gquLbvHszu4j1HKgn0a_SQ.png"/></p>
<p>I would rather the government foster the development of an independent rating scale that gives simple scores for compliance to basic hardening configurations, resistance to compromise, exposure risk to other systems, privacy, and trust of the vendorโ€™s ethics consistency.</p>
<p><img src="https://cdn-images-1.medium.com/max/800/1*8FF_MIb5DVWg7TtPUEjwWA.png"/></p>
<p>Combined with allowances to support the economics of manufacturers self-reporting, but with limited scores and only for some of the categories. An approved independent body would be required for the ratings of some categories and access to higher scores. Finally, the results must be presented in simple icons for consumers with perhaps some plain English that highlights the result</p>
<p>For comprehensiveness, labeling should be made a requirement to encourage competitiveness by vendors to deliver meaningful security for IoT products.</p>
<p>Label information must also be clear and meaningful to convey the risks to consumers. To make sure the ratings are consistent and not manipulated, independent verification will occur at a minimum in some areas, such as vendor trust, and for any area where a rating is higher than average.</p>
<p>I also caution letting the IoT manufacturing industry take the lead for any type of labeling, we risk either very complex labels, which wonโ€™t be comprehended by consumers, or overly simplistic labels that barely scratch the aspects necessary to understand the relevance of the security posture for the device or software.</p>
<p>IoT devices are easily compromised and then either used against the owner or are herded into botnets that can attack other systems on the Internet. Cybercriminals and hackers realize that the vast number of unsecured IoT devices is an excellent resource to leverage in pursuit of their goals.</p>
<p>If we are going to go down this path of security labeling, we must do it correctly for it to become a catalyst of enhanced security for these products.</p>
<p>A rational system must be proposed, where clear goals are defined which benefit consumers. Otherwise, it is a wasted effort and an unfortunate delay in addressing the systemic problem of IoT security.</p>
<p>
<br/>
<br/></p>
</html>

Posted with [STEMGeeks](https://stemgeeks.net)
๐Ÿ‘  , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , and 26 others
properties (23)
authormrosenquist
permlinkare-cybersecurity-labels-on-iot-devices-a-wasted-effort
categoryhive-163521
json_metadata{"tags":["cybersecurity","technology","iot","security","privacy","stem"],"image":["https://img.youtube.com/vi/Ohfip99riqo/0.jpg","https://cdn-images-1.medium.com/max/800/1*-5GudKx0n3foercXmBN4Ng.png","https://cdn-images-1.medium.com/max/800/1*SOvh0gWxQa-hF8ACGV6loA.png","https://cdn-images-1.medium.com/max/800/1*gquLbvHszu4j1HKgn0a_SQ.png","https://cdn-images-1.medium.com/max/800/1*8FF_MIb5DVWg7TtPUEjwWA.png"],"links":["https://www.youtube.com/embed/Ohfip99riqo"],"app":"stemgeeks/0.1","format":"html","canonical_url":"https://stemgeeks.net/@mrosenquist/are-cybersecurity-labels-on-iot-devices-a-wasted-effort"}
created2021-10-05 22:36:27
last_update2021-10-05 22:36:27
depth0
children7
last_payout2021-10-12 22:36:27
cashout_time1969-12-31 23:59:59
total_payout_value9.004 HBD
curator_payout_value8.975 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length4,956
author_reputation178,878,611,908,167
root_title"Are Cybersecurity Labels on IoT Devices a Wasted Effort"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id106,810,857
net_rshares16,003,968,532,896
author_curate_reward""
vote details (90)
@aiovo ·
$0.07
agree we need to do it the right way to benefit consumers more
๐Ÿ‘  , , , ,
properties (23)
authoraiovo
permlinkr0jquh
categoryhive-163521
json_metadata{"tags":["stem"],"app":"stemgeeks/0.1","canonical_url":"https://stemgeeks.net/@aiovo/r0jquh"}
created2021-10-06 08:13:30
last_update2021-10-06 08:13:30
depth1
children0
last_payout2021-10-13 08:13:30
cashout_time1969-12-31 23:59:59
total_payout_value0.034 HBD
curator_payout_value0.032 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length62
author_reputation15,911,295,900,579
root_title"Are Cybersecurity Labels on IoT Devices a Wasted Effort"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id106,820,116
net_rshares61,201,818,237
author_curate_reward""
vote details (5)
@alokkumar121 ·
$0.07
I dont think that its waste instead its helpful to make people aware of security and safety.
๐Ÿ‘  , , ,
properties (23)
authoralokkumar121
permlinkr0kv7o
categoryhive-163521
json_metadata{"tags":["stem"],"app":"stemgeeks/0.1","canonical_url":"https://stemgeeks.net/@alokkumar121/r0kv7o"}
created2021-10-06 22:45:27
last_update2021-10-06 22:45:27
depth1
children1
last_payout2021-10-13 22:45:27
cashout_time1969-12-31 23:59:59
total_payout_value0.033 HBD
curator_payout_value0.032 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length92
author_reputation2,489,691,104,953,059
root_title"Are Cybersecurity Labels on IoT Devices a Wasted Effort"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id106,836,643
net_rshares59,984,892,755
author_curate_reward""
vote details (4)
@mrosenquist ·
I hope so.  But they have to read and understand the labels.
properties (22)
authormrosenquist
permlinkr0n4lk
categoryhive-163521
json_metadata{"app":"hiveblog/0.1"}
created2021-10-08 04:03:21
last_update2021-10-08 04:03:21
depth2
children0
last_payout2021-10-15 04:03:21
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length60
author_reputation178,878,611,908,167
root_title"Are Cybersecurity Labels on IoT Devices a Wasted Effort"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id106,868,474
net_rshares0
@dronegirl · (edited)
$0.04
Its not a waste effort and it will help marketing and if gives the appearance that they tried to make it safe. Thats more important than that its actually safe
๐Ÿ‘  , , , ,
properties (23)
authordronegirl
permlinkr0jys3
categoryhive-163521
json_metadata{"tags":["stem"],"app":"stemgeeks/0.1","canonical_url":"https://stemgeeks.net/@dronegirl/r0jys3"}
created2021-10-06 11:04:51
last_update2021-10-06 11:17:06
depth1
children1
last_payout2021-10-13 11:04:51
cashout_time1969-12-31 23:59:59
total_payout_value0.022 HBD
curator_payout_value0.021 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length159
author_reputation268,282,759,034
root_title"Are Cybersecurity Labels on IoT Devices a Wasted Effort"
beneficiaries
0.
accounthiveonboard
weight100
1.
accounttipu
weight100
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id106,822,833
net_rshares40,984,056,087
author_curate_reward""
vote details (5)
@mrosenquist ·
I would prefer actually secure, private, and safe.
properties (22)
authormrosenquist
permlinkr0n4kr
categoryhive-163521
json_metadata{"app":"hiveblog/0.1"}
created2021-10-08 04:02:51
last_update2021-10-08 04:02:51
depth2
children0
last_payout2021-10-15 04:02:51
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length50
author_reputation178,878,611,908,167
root_title"Are Cybersecurity Labels on IoT Devices a Wasted Effort"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id106,868,466
net_rshares0
@hivebuzz ·
Congratulations @mrosenquist! You have completed the following achievement on the Hive blockchain and have been rewarded with new badge(s) :

<table><tr><td><img src="https://images.hive.blog/60x70/http://hivebuzz.me/@mrosenquist/upvoted.png?202110061838"></td><td>You received more than 35000 upvotes.<br>Your next target is to reach 40000 upvotes.</td></tr>
</table>

<sub>_You can view your badges on [your board](https://hivebuzz.me/@mrosenquist) and compare yourself to others in the [Ranking](https://hivebuzz.me/ranking)_</sub>
<sub>_If you no longer want to receive notifications, reply to this comment with the word_ `STOP`</sub>



**Check out the last post from @hivebuzz:**
<table><tr><td><a href="/hivebuzz/@hivebuzz/pud-202110-feedback"><img src="https://images.hive.blog/64x128/https://i.imgur.com/zHjYI1k.jpg"></a></td><td><a href="/hivebuzz/@hivebuzz/pud-202110-feedback">Feedback from the October 1st Hive Power Up Day</a></td></tr><tr><td><a href="/hivebuzz/@hivebuzz/pum-202109-final"><img src="https://images.hive.blog/64x128/https://i.imgur.com/lpF7k06.png"></a></td><td><a href="/hivebuzz/@hivebuzz/pum-202109-final">Hive Power Up Month Challenge - Winners List</a></td></tr></table>
๐Ÿ‘  
properties (23)
authorhivebuzz
permlinkhivebuzz-notify-mrosenquist-20211006t185907
categoryhive-163521
json_metadata{"image":["http://hivebuzz.me/notify.t6.png"]}
created2021-10-06 18:59:06
last_update2021-10-06 18:59:06
depth1
children0
last_payout2021-10-13 18:59:06
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length1,206
author_reputation370,640,322,869,961
root_title"Are Cybersecurity Labels on IoT Devices a Wasted Effort"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id106,832,335
net_rshares9,880,322,839
author_curate_reward""
vote details (1)
@ultimus ·
$0.25
Nutrition labels all over again. So many ways to hide or mischaracterize bad elements.  
They need to get this right!
๐Ÿ‘  , , , ,
properties (23)
authorultimus
permlinkr0j139
categoryhive-163521
json_metadata{"app":"hiveblog/0.1"}
created2021-10-05 22:57:12
last_update2021-10-05 22:57:12
depth1
children0
last_payout2021-10-12 22:57:12
cashout_time1969-12-31 23:59:59
total_payout_value0.123 HBD
curator_payout_value0.123 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length117
author_reputation6,664,676,750,516
root_title"Are Cybersecurity Labels on IoT Devices a Wasted Effort"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id106,811,264
net_rshares221,473,021,029
author_curate_reward""
vote details (5)