Re: Access control for IoT
Alan Karp <[email protected]> Sat, 16 Jan 2016 09:59:47 -0800
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CANpA1Z3EUtTa7xjWtaMzedwE7BA5S3a+JKFojinbjOk2qPj-cw@mail.gmail.com> |
--===============1082387967415113836== Content-Type: multipart/alternative; boundary=001a11410200137c600529774959 --001a11410200137c600529774959 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable I think one reason for lack of interoperability is the desire for lock-in by the vendors. Another is lack of standards. As far as privacy versus functionality, I believe 99+% of people will choose the latter without blinking an eye. -------------- Alan Karp On Sat, Jan 16, 2016 at 7:51 AM, Tim Coote <[email protected]> wrote: > Good to see some other points of view on IoT security. This is one of the > specific issues that triggered my joining this list! > > I=E2=80=99ve been struggling to get the point over about authorisation tr= ansfer to > various groups and found that they generally agree intellectually, but > still seem to think in terms of authentication creating authorisation. > Naming is another related issue. I=E2=80=99d concluded that Things in IoT= shouldn=E2=80=99t > be identified just with individual hardware objects, even though the mode= l > has value from a usability point of view (esp. when things go wrong). In > fact, most current IoT devices are much too clever to easily compose and > get useful compound behaviours out of. The issue seems to be a tension > between makers of Things and service providers who are more interested in > the Internet aspects. The different interests create different motivation= s > over features vs control (inc. security). > > I=E2=80=99d be intrigued on points of view on privacy issues to do with a= ggregated > data. All providers that I=E2=80=99ve worked encountered are salivating a= t mining > behavioural and other data. So the question is, will general users get so > spooked that they will only use well controlled systems or will they cove= t > the functionality more. I=E2=80=99m pitching the former, but can see an a= rgument > for the latter. If the former is true, then I=E2=80=99ve concluded that t= he > provider of the IoT service needs an opt-in policy for retaining any data= . > (Datensparsamkeit, as I=E2=80=99ve seen the approach described). > > tc > > On 15 Jan 2016, at 23:13, Alan Karp <[email protected]> wrote: > > For reasons that I don't understand, I got a slot at an invitation only > IEEE workshop on security and privacy for IoT. (Maybe not enough people > are willing to go to Washington, DC, in February.) Invitees can submit > papers, and 15 will be selected for presentation. Mine is at > http://alankarp.parseapp.com/Access-Control-for-IoT.pdf. > > The submission deadline has passed, so it's too late for me to fix any > errors. However, if you find things that need changing, I can address th= em > in the presentation should I get one of the slots. > > -------------- > Alan Karp > _______________________________________________ > cap-talk mailing list > [email protected] > http://www.eros-os.org/mailman/listinfo/cap-talk > > > > _______________________________________________ > cap-talk mailing list > [email protected] > http://www.eros-os.org/mailman/listinfo/cap-talk > > --001a11410200137c600529774959 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">I think one reason for lack of interoperability is the des= ire for lock-in by the vendors.=C2=A0 Another is lack of standards.<div><br= ></div><div>As far as privacy versus functionality, I believe 99+% of peopl= e will choose the latter without blinking an eye.=C2=A0</div></div><div cla= ss=3D"gmail_extra"><br clear=3D"all"><div><div class=3D"gmail_signature"><b= r>--------------<br>Alan Karp</div></div> <br><div class=3D"gmail_quote">On Sat, Jan 16, 2016 at 7:51 AM, Tim Coote <= span dir=3D"ltr"><<a href=3D"mailto:[email protected]" target=3D= "_blank">[email protected]</a>></span> wrote:<br><blockquote cla= ss=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;pa= dding-left:1ex"><div style=3D"word-wrap:break-word">Good to see some other = points of view on IoT security. This is one of the specific issues that tri= ggered my joining this list!<div><br></div><div>I=E2=80=99ve been strugglin= g to get the point over about authorisation transfer to various groups and = found that they generally agree intellectually, but still seem to think in = terms of authentication creating authorisation. Naming is another related i= ssue. I=E2=80=99d concluded that Things in IoT shouldn=E2=80=99t be identif= ied just with individual hardware objects, even though the model has value = from a usability point of view (esp. when things go wrong). In fact, most c= urrent IoT devices are much too clever to easily compose and get useful com= pound behaviours out of.=C2=A0 The issue seems to be a tension between make= rs of Things and service providers who are more interested in the Internet = aspects. The different interests create different motivations over features= vs control (inc. security).<div><br></div><div>I=E2=80=99d be intrigued on= points of view on privacy issues to do with aggregated data. All providers= that I=E2=80=99ve worked encountered are salivating at mining behavioural = and other data. So the question is, will general users get so spooked that = they will only use well controlled systems or will they covet the functiona= lity more. I=E2=80=99m pitching the former, but can see an argument for the= latter. If the former is true, then I=E2=80=99ve concluded that the provid= er of the IoT service needs an opt-in policy for retaining any data. (Daten= sparsamkeit, as I=E2=80=99ve seen the approach described).</div><div><br></= div><div>tc</div><div><div><blockquote type=3D"cite"><div>On 15 Jan 2016, a= t 23:13, Alan Karp <<a href=3D"mailto:[email protected]" target=3D"_bl= ank">[email protected]</a>> wrote:</div><br><div><div dir=3D"ltr">For = reasons that I don't understand, I got a slot at an invitation only IEE= E workshop on security and privacy for IoT. =C2=A0(Maybe not enough people = are willing to go to Washington, DC, in February.) =C2=A0Invitees can submi= t papers, and 15 will be selected for presentation.=C2=A0 Mine is at <a hre= f=3D"http://alankarp.parseapp.com/Access-Control-for-IoT.pdf" target=3D"_bl= ank">http://alankarp.parseapp.com/Access-Control-for-IoT.pdf</a>.<div><br><= /div><div>The submission deadline has passed, so it's too late for me t= o fix any errors.=C2=A0 However, if you find things that need changing, I c= an address them in the presentation should I get one of the slots.<br clear= =3D"all"><div><div><br>--------------<br>Alan Karp</div></div> </div></div> _______________________________________________<br>cap-talk mailing list<br= ><a href=3D"mailto:[email protected]" target=3D"_blank">cap-talk@ma= il.eros-os.org</a><br><a href=3D"http://www.eros-os.org/mailman/listinfo/ca= p-talk" target=3D"_blank">http://www.eros-os.org/mailman/listinfo/cap-talk<= /a><br></div></blockquote></div><br></div></div></div><br>_________________= ______________________________<br> cap-talk mailing list<br> <a href=3D"mailto:[email protected]">[email protected]</a><= br> <a href=3D"http://www.eros-os.org/mailman/listinfo/cap-talk" rel=3D"norefer= rer" target=3D"_blank">http://www.eros-os.org/mailman/listinfo/cap-talk</a>= <br> <br></blockquote></div><br></div> --001a11410200137c600529774959-- --===============1082387967415113836== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk --===============1082387967415113836==--