SearcharxivSearch

arXiv subjects

Veerle van Harten

Publications and source records attributed to Veerle van Harten.

2 recordsLinked to original sources

"Am I Just Dumb?": Applicability, Action and Verification in Consumer IoT Security Advice

Public campaigns urge people to update their Internet of Things (IoT) devices and change default passwords. What happens when people try? We gave 28 participants in the Netherlands two pieces of government-issued advice and asked them to try applying each to three of six bestselling IoT devices (168 sessions). We located no manufacturer-set password shared across units, the kind the advice describes; the only device-level credential located was unique to its unit. Fewer than half the update sessions established firmware status. Told that a setting might not apply, no participant concluded it did not: they treated whatever related setting the interface offered as the target, and located the difficulty in themselves rather than in the advice or device. Generic advice asks people to judge what only manufacturers can state and only devices can report. Campaigns must be coordinated with device design, or replaced by secure defaults that remove the task.

cs.HC

Easier Said Than Done: The Failure of Top-Level Cybersecurity Advice for Consumer IoT Devices

Consumer IoT devices are generally assumed to lack adequate default security, thus requiring user action. However, it may not be immediately clear to users what action to take and how. This uncertainty begs the question of what the minimum is that the user-base can reliably be asked to do as a prompt to secure their devices. To explore this question, we analyze security actions advocated at a national level and how these connect to user materials for a range of specific devices. We identify four pieces of converging advice across three nation-level initiatives. We then assess the extent to which these pieces of advice are aligned with instruction materials for 40 different IoT devices across five device classes (including device manuals and manufacturer websites). We expose a disconnect between the advice and the device materials. A stunning finding is that there is not a single assessed device to which all four top pieces of converging advice can be applied. At best, the supporting materials for 36 of the 40 devices provide sufficient information to apply just two of the four pieces of advice, typically the installation and enabling of (auto)updates. As something of a contradiction, it is necessary for a non-expert user to assess whether expert advice applies to a device. This risks additional user burden and proxy changes being made without the proposed security benefits. We propose recommendations, including that governments and researchers alike should declare their own working models of IoT devices when considering the user view.

cs.CR