←back to thread

265 points methuselah_in | 4 comments | | HN request time: 0s | source
Show context
losthobbies ◴[] No.44366283[source]
Dodgy IoT devices will be the end of us all.
replies(1): >>44366592 #
bearjaws ◴[] No.44366592[source]
It's wild to think with the proliferation of 1gbps fiber internet, even a modern pi board or old desktop is a potential 1gbps bot host.
replies(3): >>44366877 #>>44369703 #>>44376673 #
franga2000 ◴[] No.44369703[source]
When your IP is found to have been part of a botnet, I think ISPs should just limit you to like 20Mbps for at least a year, so you think twice about buying that 10$ wifi baby monitor next time.
replies(6): >>44370378 #>>44370602 #>>44371379 #>>44380821 #>>44384044 #>>44392890 #
bogdan ◴[] No.44370378[source]
That's quite harsh. Good thing you're not in charge of making decisions.
replies(2): >>44371577 #>>44372154 #
mschuster91 ◴[] No.44372154[source]
When you get caught speeding on the road or being a nuisance otherwise you can and will get punished by the courts, including temporary restrictions on your driver license. When you money mule for others, even if you don't know that you actually fell victim to a scam, you get punished as well. When you litter in Singapore, you can get ordered to work community service.

I see no issue in handing out similar punishments in the digital space. The Internet is a shared medium, everyone who connects to it has a responsibility to not be a nuisance to others.

replies(2): >>44372649 #>>44392878 #
xwolfi ◴[] No.44372649[source]
On the road you could have killed someone. Your 20$ baby monitor bought from an authorized store you know... whatever happens, it's not gonna kill anyone very directly ...

The main ingredient of crime is intent, whatever you say. A smaller ingredient can be recklessness, but maybe it's the ISPs sending all those millions of empty packets to a single server that should start feeling some heat ?

replies(1): >>44376237 #
mschuster91 ◴[] No.44376237[source]
> Your 20$ baby monitor bought from an authorized store you know... whatever happens, it's not gonna kill anyone very directly ...

Yeah, not kill, but participating in a DDoS against a heavily frequented commercial site that makes hundreds of thousands of dollars of revenue a minute, that's still some substantial damage.

In the end it should boil down to the ability of holding the seller of the product with security issues accountable for the damages, and the seller in turn can hold the manufacturer accountable. Maybe that will lead to some substantial change.

replies(2): >>44377559 #>>44384067 #
1. Spivak ◴[] No.44377559[source]
You are ignoring the fact that the criminal in question bought a baby monitor. that is the full extent of their crime.

A person who buy all reason has absolutely no idea how any of this shit works. If you wanna go after somebody go after the manufacturer of said baby monitor.

replies(1): >>44383745 #
2. Khaine ◴[] No.44383745[source]
A person who buys a Tesla has no idea how any of it works.

Look at the moment, the owner of devices that participate in DDoSes are not head liable, and neither are manufacturers who don't secure their shit.

This needs to change.

replies(2): >>44384077 #>>44392924 #
3. motorest ◴[] No.44384077[source]
Please explain in your own words why I should be liable for a third party misappropriating a product I own.
4. NoPicklez ◴[] No.44392924[source]
A person who buys a Tesla has no idea how any of it works, but if someone breaks into that car and drives it (non-autonomously) into pedestrians how would I be held liable for that? I wouldn't be and shouldn't be. The person who broke into the car and drove it would be, the difference here is that the perpetrator is harder to catch so people look to blame something else.

At the end of the day it is very difficult to impose security management across consumers. You cannot expect the average consumer to pen test their home network and have active vulnerability scanning software to mitigate potential vulnerabilities that result in Botnets.

It is difficult to hold people liable when someone else misappropriates their assets in a way that was not its original intended purpose. When its difficult to capture the perpetrator people start to blame everything else, that doesn't mean we should just shift liability to the buyer who is just simply an easier target to place the blame on than a random unidentified person in another country.

That may sound like a solution but its not the right one. Now someone has the ability to misappropriate your assets from the other side of the world and you become charged with the crime, when all you did was buy a new Samsung TV. Heck knowing that, maybe someone would target you knowing full well you'd be in trouble for it.