Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Tragedy of the commons. No individual manufacturer really cares about the issues created by the ecosystem of IoT, so they have no real incentive to address it.


Tragedy of the Commons really means "the structure of a market failed to produce the desired outcome". The common good may be the victim, but the market is the culprit.

The solution of course is alternate economic structures that respect the commons. The distinguished economist Elinor Ostrom wrote a whole book called Governing the Commons which presents real-life alternatives to markets for commons-like economic activity.

Or we could continue marching to the drum of neoliberalism and try to contort markets until they meet our needs. Love me some procrustean capitalism.


Assuming you've already read that book, can you elaborate how would those strategies help in this case and what kind of changes would they imply?


I thought neoliberalism was more about contorting society until they meet the needs of the market.


Two sides of the same process: force markets to exist where they didn't or shouldn't.


Sure, but it's not a symmetrical or reflexive relationship.


The opposing viewpoint is that only public resources suffer from tragedies of the common (they become a free-for-all), whereas with private ownership there's usually a natural incentive to make your profit-producing resource sustainable. Of course, it's always more nuanced than that (mining and resource extraction industries are problematic), the ideal is probably somewhere in the middle. So we argue about exactly where it should be :)


The situation you are lamenting (and I agree with your sentiment) is not a "tragedy of the commons." I think you are trying to describe a collective action problem. Collective action problems are frequently brought up during a discussion of the tragedy of the common but the existence of a collective action problem does not imply that there is a tragedy of the commons. If you are interested in these types of issues Mancur Olsen's "The Logic of Collective Action" is the standard introduction.


Any manufacturer who has to recall a device cares very much about it.


Those IoT manufacturers must be lucky then. They haven't been sued because of a insecure lightbulb yet.


"Yet" is the key word. Even rumors are sometimes enough and as powerful as lawsuits.

Market forces are really powerful. See Samsung's recent troubles -- once everything was fine, and then -- BAMM! - their phone sales went down without any external regulation. (pun intended.)


How is this "tragedy of the commons"? The only "common" they are using is the RF spectrum, which they are presumably not polluting too badly or the FCC would start smashing down doors.

Let's not start claiming the internet itself somehow qualifies as a "common", because with common ownership rationally comes common censorship (as with the FCC and public broadcasts).


I think you are mistaking "tragedy of the commons". It is a behavioral outcome, where individual actors take actions that immediately benefit them, but if everyone else does the same thing, then no one wins. Overfishing a public pond is a common example (the commons is obvious here: the pond), but another great example is standing up to get a better view at a large stadium event. If you stand up, you can see better. Unfortunately, this means the person behind you also has to stand up. Once everyone is standing up, no one is any better off than if they were all sitting.

The analogy here is more like the latter: It is better for Manufacturer X to rush their IoT device to market to maximize profits, ignoring security concerns. If every manufacturer does this (the person in front of you at the stadium just stood up, so you stand up too), then whoa, we have millions of insecure devices waiting to be exploited. This is indeed a tragedy of the commons.


Seems unwise to reason backwards from your desired conclusion (commons implies censorship/regulation, so it can't be a commons).

Security is indeed a commons because the overall security of the ecosystem only benefits each person weakly, and so every actor rationally benefits by neglecting security.

External regulation isn't the only way to address commons problems. Manufacturers can see the writing on the wall and work together to solve issues, but only if the public pushes them to.


I imagine that it can also get better once a company can gain competitive advantage by advertising that "our device is secure!" But I suppose a precondition for this is customer awareness of the issue, which probably requires some well publicized high impact/casualty incidents first? :/


> But I suppose a precondition for this is customer awareness of the issue, which probably requires some well publicized high impact/casualty incidents first? :/

I'd say it absolutely requires a high-impact case, something like downing of an airplane, or a cyberattack that sets half of the city in flames. Otherwise, any concern of people about security will quickly get papered over by marketing - as it always is.


Of course, anyone can say "our device is secure", and if the industry is left to its own devices to create a standard for being allowed to say that, they'll pick the cheapest standard possible. Then, so long as they can say "we were following the standards", and the standards company can say "we're updating the standard" every time, nobody cares.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: