Tuesday, February 16, 2016

Week 10--The IoT and Surveillance

Last week, the Director of National Intelligence James Clapper submitted this statement to Congress as part of an assessment of threats facing the United Sates:
In the future, intelligence services might use the [internet of things] for identification, surveillance, monitoring, location tracking, and targeting for recruitment, or to gain access to networks or user credentials.
The IoT is insecure and growing rapidly. Components of the IoT are also often equipped with useful accessories and sensors that facilitate information collection; Amazon Echo, for example, is equipped with a microphone for picking up voice commands, a thermostat has temperature sensors (among other things), and a vehicle has sensors describing the state of the vehicle in real-time. IoT devices also have computing capabilities and connect to the Internet--essentially creating a web of insecure sensory devices spread across the world and accessible to anyone who wants to put the effort into breaking in.
What is troubling about Mr. Clapper's statement is that using the IoT to monitor people inherently relies on the insecurity of the system. If all webcams, vehicles, and other IoT devices use uncrackable encryption, utilize strong password identification, and are secure in every other InfoSec way, then surveillance functions of the government will need to rely on explicit permission from the devices' owners or will have to create laws allowing them access by force. The first option is unfeasible (who would give up their devices to Uncle Sam?) and the second would likely fail so long as the United States is a democracy. People like their privacy, and they won't let surveillance laws be passed on them without a fight.
So what will the NSA and other surveillance teams likely do?
Rely on the laxness of current IoT security to perform surveillance. In other words, in using the IoT as it currently exists for surveillance, governing agencies are gaining a vested interest in the continuing insecurity of the IoT. If they use the IoT for surveillance, then advancing IoT security will only make their job harder.
That's bad.
Insecure devices are a problem, since they leave their owners constantly vulnerable to surveillance. Information like this in a malicious person's hands can provide them enough evidence to perform any number of evil actions. Thus, security is needed. But businesses won't secure devices just because it's the right thing--if people want the IoT in spite of its insecurities, then who is the business to judge? Now, according to James Clapper the government will be less and less inclined to force businesses to implement security measures. In other words, neither businesses nor the government over the businesses are likely to push for security in the IoT--at least, security that the customer has control over.
Now, the government may push for security so long as it prohibits other users from using the IoT. However, they will not likely advocate for security measures that people could use to limit the government's surveillance capabilities. As the saga of IoT security continues to evolve, one thing is for certain: if you want to have IoT security, then you had better stand up and say something, because people bigger than you are happy with it just the way it is.

No comments:

Post a Comment