Internet of things devices, which are often impossible to patch, will remain insecure unless government steps in to regulate the industry
Brian Krebs is a popular reporter on the cybersecurity beat. He regularly exposes cybercriminals and their tactics, and consequently is regularly a target of their ire.
Context & Ripple Effects
This argument lands at the end of a run of coverage building the same case from different angles: an August Motherboard piece warned that the rise of connected devices makes cyberattacks capable of real-world physical damage, and Brian Krebs followed in late September by calling on the Internet community to adopt standards because insecure IoT devices make large-scale DDoS attacks more potent.
What changes here is the prescription: voluntary patching and community standards are declared insufficient for devices that often cannot be patched at all, leaving government regulation as the remaining lever. That framing matters because it converts a technical problem into a policy one.
First-order effects
- Buyers of consumer IoT hardware are stuck with devices whose firmware cannot be updated, meaning every unpatched unit shipped stays vulnerable for its full service life.
- Device makers face a new accountability question: with patching off the table, their design-time security decisions become permanent commitments they cannot retroactively fix.
Second-order effects
- Infrastructure operators and websites absorbing amplified DDoS traffic sourced from compromised home devices will keep paying the cost of other vendors' insecure products, strengthening the case for liability or minimum-security rules.
- Standards efforts like those Krebs urged the Internet community to adopt become the industry's chance to self-regulate before regulators impose something stricter.
Third-order effects
- If unpatchable devices persist, security shifts upstream to procurement and supply chains — a theme the corpus returns to two years later with the argument that [[a:934250|attacks like the alleged Chinese embedded chip hack are basically impossible to fully prevent]], only mitigate.
- The realistic endpoint is a split market: regulated, certifiable devices for anything touching critical functions, and a residual insecure tier that governments may eventually try to fence off from networks.
The trend: IoT security is migrating from voluntary patching and community standards toward government-mandated baseline requirements, driven by devices that ship unable to be fixed.