Internet of things devices, which are often impossible to patch, will remain insecure unless government steps in to regulate the industry
Bruce Schneier / Motherboard :
Context & Ripple Effects
Bruce Schneier's Motherboard column lands at the end of a year of accumulating evidence that consumer IoT is a security liability: an August piece warned that connected devices make cyberattacks capable of real-world damage, and a September report found over 4.5 million network appliances and embedded systems exposed by reused private keys on HTTPS and SSH servers. Krebs on Security separately argued that insecure devices are making large-scale DDoS attacks more potent and called for standards and defensive tools.
First-order effects
- Device manufacturers shipping unpatchable hardware face a direct challenge to their status quo: Schneier's argument targets exactly the business model that treats security updates as someone else's problem.
Second-order effects
- If governments act, compliance costs shift to vendors — disclosure of update lifecycles, unique per-device credentials, and patchability become market-entry requirements rather than differentiators.
Third-order effects
- The pattern points toward security regulation as a condition of selling connected hardware, much as safety certification governs physical goods; the UK government's later proposal to mandate update-duration disclosures and unique passwords shows regulators picking up precisely this playbook.
The trend: IoT security is moving from voluntary vendor practice toward government-mandated baseline requirements, driven by the attack surface these devices create.