<div dir="auto">+1<div dir="auto"><br></div><div dir="auto">Now how do we get the tech industry to embrace it? They have $$$$$ and can lobby against this so they must instead be redirected to support this. Then they use the $$$$$ the they steal from us (profits) to lobby to curtail bad corp behavior. Then we get laws.</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Jun 8, 2017 9:14 AM, &quot;DJ-Pfulio&quot; &lt;<a href="mailto:djpfulio@jdpfu.com">djpfulio@jdpfu.com</a>&gt; wrote:<br type="attribution"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Which is why - and I can&#39;t believe I&#39;m saying this - we need national laws<br>
(cough, cough, cough) to mandate support periods (5-10 yrs?) and mandatory<br>
patching at least quarterly for all connected devices if more than 200 are sold.<br>
<br>
&quot;connected&quot; means **any** networking capability.<br>
<br>
The penalties need to be &gt;&gt; corporation ending &lt;&lt; for failure to comply and tied<br>
to the management team, so they cannot be serial failures selling the same basic<br>
thing and going out of business every few years.<br>
<br>
Plus, this will prevent companies from adding networking, unless there is a<br>
really good reason, due to the patching required - looking at many TVs.<br>
<br>
I&#39;m tired of Google thinking a $300-$1500 device has a 3 yr life.<br>
_Supported-until at-least_ dates on packaging, mandatory. If a company is sold,<br>
those support dates MUST be carried forward. Sorta a poison pill to prevent that<br>
old loophole.<br>
<br>
I&#39;m tired of router companies putting out crap $20-$250 routers and NEVER making<br>
any patches available. Yes, many of those $250 routers are crap.<br>
<br>
<br>
On 06/08/2017 08:45 AM, Jim Kinney wrote:<br>
&gt; The merest hint of &quot;set and forget&quot; devices left live online forever scares the<br>
&gt; poo out of me. Colossally stupid idea. Add the &quot;use of this device releases the<br>
&gt; manufacturer of all liability&quot; license crap and it starts looking like a smokers<br>
&gt; convention at a fireworks factory.<br>
&gt;<br>
&gt; There&#39;s a responsibility level that software production just hasn&#39;t accepted<br>
&gt; yet. Sometimes &#39;release early, release often&#39; is really translated to &#39;break<br>
&gt; early, break often, release anyway&quot;.<br>
&gt;<br>
&gt;<br>
&gt;<br>
&gt; On Jun 8, 2017 8:31 AM, &quot;DJ-Pfulio&quot; &lt;<a href="mailto:DJPfulio@jdpfu.com">DJPfulio@jdpfu.com</a><br>
&gt; &lt;mailto:<a href="mailto:DJPfulio@jdpfu.com">DJPfulio@jdpfu.com</a>&gt;&gt; wrote:<br>
&gt;<br>
&gt;     Perhaps IoT devices need this too?<br>
&gt;<br>
&gt;     Bruce Schneier&#39;s blog ...<br>
&gt;     <a href="https://www.schneier.com/blog/archives/2017/06/safety_and_secu.html" rel="noreferrer" target="_blank">https://www.schneier.com/blog/<wbr>archives/2017/06/safety_and_<wbr>secu.html</a><br>
&gt;     &lt;<a href="https://www.schneier.com/blog/archives/2017/06/safety_and_secu.html" rel="noreferrer" target="_blank">https://www.schneier.com/<wbr>blog/archives/2017/06/safety_<wbr>and_secu.html</a>&gt;<br>
&gt;     &quot;Last year, on October 21, your digital video recorder — or at least a<br>
&gt;     DVR like yours — knocked Twitter off the internet. Someone used your<br>
&gt;     DVR, along with millions of insecure webcams, routers, and other<br>
&gt;     connected devices, to launch an attack that started a chain reaction,<br>
&gt;     resulting in Twitter, Reddit, Netflix, and many sites going off the<br>
&gt;     internet. You probably didn&#39;t realize that your DVR had that kind of<br>
&gt;     power. But it does.&quot;<br>
&gt;<br>
&gt;<br>
&gt;     A few years ago during a national election is a smaller country, the<br>
&gt;     entire country was taken off line using internet attacks.<br>
&gt;<br>
&gt;     IoT (or Internet of Shit-devices) have amplified this power.<br>
&gt;<br>
&gt;<br>
&gt;     On 06/08/2017 08:09 AM, Jim Kinney wrote:<br>
&gt;     &gt; Hah!<br>
&gt;     &gt;<br>
&gt;     &gt; Sad but true.<br>
&gt;     &gt;<br>
&gt;     &gt; Certain aspects of programming should be required to be<br>
&gt;     &gt; run/directed/managed by licensed professional engineers. Finance,<br>
&gt;     &gt; utilities, and medical are the top three for me that scream for real<br>
&gt;     &gt; professional programming. We don&#39;t let precocious high schoolers build<br>
&gt;     &gt; bridges just because they were really good with lego blocks. Engineering<br>
&gt;     &gt; of physical things protects itself with professional standards.<br>
&gt;     &gt; Engineering of virtual things needs to do the same.<br>
&gt;     &gt;<br>
&gt;     &gt; On Jun 8, 2017 7:44 AM, &quot;Adrya Stembridge&quot; &lt;<a href="mailto:adrya.stembridge@gmail.com">adrya.stembridge@gmail.com</a><br>
&gt;     &lt;mailto:<a href="mailto:adrya.stembridge@gmail.com">adrya.stembridge@<wbr>gmail.com</a>&gt;<br>
&gt;     &gt; &lt;mailto:<a href="mailto:adrya.stembridge@gmail.com">adrya.stembridge@<wbr>gmail.com</a> &lt;mailto:<a href="mailto:adrya.stembridge@gmail.com">adrya.stembridge@<wbr>gmail.com</a>&gt;&gt;&gt;<br>
&gt;     wrote:<br>
&gt;     &gt;<br>
&gt;     &gt;     For $250 they got about what they paid for.<br>
&gt;     &gt;<br>
&gt;     &gt;     On Thu, Jun 8, 2017 at 6:42 AM, DJ-Pfulio &lt;<a href="mailto:DJPfulio@jdpfu.com">DJPfulio@jdpfu.com</a><br>
&gt;     &lt;mailto:<a href="mailto:DJPfulio@jdpfu.com">DJPfulio@jdpfu.com</a>&gt;<br>
&gt;     &gt;     &lt;mailto:<a href="mailto:DJPfulio@jdpfu.com">DJPfulio@jdpfu.com</a> &lt;mailto:<a href="mailto:DJPfulio@jdpfu.com">DJPfulio@jdpfu.com</a>&gt;&gt;&gt; wrote:<br>
&gt;     &gt;<br>
&gt;     &gt;         Of the 17 commissioned projects by Tripwire (a security firm), 10<br>
&gt;     &gt;         websites were completed and purchased.<br>
&gt;     &gt;<br>
&gt;     &gt;         The researchers found that every website had critical security<br>
&gt;     &gt;         failures.<br>
&gt;     &gt;         Read more here:<br>
&gt;     &gt;<br>
&gt;     &gt;         <a href="https://www.helpnetsecurity.com/2017/06/08/website-security/" rel="noreferrer" target="_blank">https://www.helpnetsecurity.<wbr>com/2017/06/08/website-<wbr>security/</a><br>
&gt;     &lt;<a href="https://www.helpnetsecurity.com/2017/06/08/website-security/" rel="noreferrer" target="_blank">https://www.helpnetsecurity.<wbr>com/2017/06/08/website-<wbr>security/</a>&gt;<br>
&gt;     &gt;         &lt;<a href="https://www.helpnetsecurity.com/2017/06/08/website-security/" rel="noreferrer" target="_blank">https://www.helpnetsecurity.<wbr>com/2017/06/08/website-<wbr>security/</a><br>
&gt;     &lt;<a href="https://www.helpnetsecurity.com/2017/06/08/website-security/" rel="noreferrer" target="_blank">https://www.helpnetsecurity.<wbr>com/2017/06/08/website-<wbr>security/</a>&gt;&gt;<br>
&gt;     &gt;<br>
&gt;     &gt;         * Unauthorized users allowed (all) - Check<br>
&gt;     &gt;         * Allowed hackers to upload a PHP webshell (all) - Check<br>
&gt;     &gt;         * Allowed auth bypass via SQL injection (several) - Check<br>
&gt;     &gt;         * Allowed content modification via SQL injection (half) - Check<br>
&gt;     &gt;<br>
&gt;     &gt;         Short, but interesting read.<br>
&gt;<br>
<br>
______________________________<wbr>_________________<br>
Ale mailing list<br>
<a href="mailto:Ale@ale.org">Ale@ale.org</a><br>
<a href="http://mail.ale.org/mailman/listinfo/ale" rel="noreferrer" target="_blank">http://mail.ale.org/mailman/<wbr>listinfo/ale</a><br>
See JOBS, ANNOUNCE and SCHOOLS lists at<br>
<a href="http://mail.ale.org/mailman/listinfo" rel="noreferrer" target="_blank">http://mail.ale.org/mailman/<wbr>listinfo</a><br>
</blockquote></div></div>