Evaluate 权衡您正在考虑的技术,产品和项目的利弊。


What can sheep teach us about securing IoT? To understand the dilemma represented by the need to have secure devices, think about the problem in terms of collective ownership, like sheep grazing in a commonly owned pasture.

1968年,一位名叫格雷特·哈丁(Garret Hardin)的进化生物学家发表了一篇论文Sciencewith the title “The Tragedy of the Commons.” In it, he described a scenario in which the land provided adequate sustenance for the herd, so long as the number of sheep was kept in check. If each person who grazed on that land acted in their own self-interest and increased the number of sheep they sent to pasture, the land would eventually become insufficient to support the population and, in turn, would be overgrazed to the point where it would it would be unable to support the community that relied upon it. The problem stems from the fact that no single entity in the community is incentivized to take care of the pasture and, as a result, everyone suffers.

Over the past 10 years, the internet has seen an explosion of connected devices that can deliver YouTube to your various screens, unlock doors, adjust temperature from a distance and transmit energy usage to your local utility. And just like the pasture, the internet is a “commons” that has benefits and drawbacks because no one controls it.

虽然我们都从智能,连接的设备提供的舒适性和便利性中受益,但这些相同设备的安全性缺乏安全性。虽然当然不是一个孤立的案件,Mirai攻击发生在2016年底,并使用了仅使用无法修改的默认工厂密码保护的IP安全摄像机。即使用户愿意这样做,这些相机也无法保护。在这种情况下,黑客修补了安全孔,大概是其他人可以控制密码,并利用它来控制IP摄像机,并使用其带宽到放下最大名称服务之一on the internet. These name services are the equivalent of the Yellow Pages of the internet. Web services rely on them to talk to one another. The attack caused several high-profile services like Twitter, Netflix and Reddit to go offline and infected an estimated 500,000 devices.

当前的问题是:谁激励着保护物联网?应该公司producing connected chips负责启用安全设备?应该责任落到设备制造商,就像制造恒温器或汽车的人一样?还是我们需要政府法规来为可接受的基准设定基准?

To have the government look at IoT security would mean someone is taking responsibility for management of the “internet commons,” but there are challenges on both sides of regulation. Too much has consequences, as does too little.


所有这些额外的安全性和认证增加了成本,并延长了产品上市所需的时间。对于大型公司和昂贵的产品,这可能是可以管理的,但是它确实为小公司或低成本/高批量产品(例如连接的灯泡or window contact sensors. And a lot of the innovation comes from small companies with new ideas, so barriers of entry clearly thwart innovation.



In fact, a year ago the exclusive Austrian hotel Romantik Seehotel Jaegerwirt was subject to a ransom event when hackers took control of the connected door locks and held out for payment. The hotel has plans to retrofit now with mechanical locks.

今天我们知道黑客可以访问U.S. energy grid还有一些团队为如何封闭安全漏洞而奋斗,但是数十亿个无抵押的连接设备为不良演员提供了攻击向量,这些攻击者几乎无法预料和捍卫。


那么正确的监管级别是多少?这可能是安全风险与可接受的风险的平衡。今天,美国政府敦促物联网设备的半导体供应商和制造商考虑网络安全during the design phase。它还主张对连接产品进行销售和生命周期监测,以检测和防止脆弱性。

As the government is on the verge of requiring连接设备的最低安全性in Federal buildings, it seems to be counting on the purchasing power of the government to be a force for change. As regulations for IoT security are developed, here are three principles we’d like to see applied:

  1. The government should be proactive about planning for regulation. Politics are intrinsically reactive, but it would be best to ensure regulations are not a knee-jerk reaction to high-profile hacks or newspaper headlines.
  2. 法规和要求应进行审查,并通过制定路线图并创建法规的更新来进行广泛传达。这样,产品设计周期可以预测变化并适应。
  3. Any regulation should be done with a global perspective and market alignment. Many IoT devices are made for global markets, and if every country invents its own regulations and requirements with subtle differences, it will become very expensive and unmanageable for most companies to comply.


