profile-img
CyLab

@CyLab

CyLab is @CarnegieMellon's Security & Privacy Institute. Our 300+ researchers are passionate about creating a world in which technology can be trusted.

calendar_today02-04-2009 13:18:44

6,8K Tweets

9,8K Followers

1,6K Following

CyLab(@CyLab) 's Twitter Profile Photo

(1/6) CyLab director Lorrie Cranor along with Yuvraj Agarwal and Omer Akgul joined forces with Consumer Reports to request amendments to the The FCC's Cybersecurity Labeling for Internet of Things Order, to be voted on by the this week: cylab.cmu.edu/_files/documen…

account_circle
CyLab(@CyLab) 's Twitter Profile Photo

(2/6) We’re concerned that the current order omits critical privacy and security information and does not do enough to address consumers’ needs. The CyLab/CR letter asks the FCC to amend the order to correct three problems:

account_circle
CyLab(@CyLab) 's Twitter Profile Photo

(3/6) The FCC order specifies labels on IoT device packaging with QR codes and the US Cyber Trust Mark and assumes that consumers will all scan the QR codes to get more information.

account_circle
CyLab(@CyLab) 's Twitter Profile Photo

(4/6) However, our research shows that consumers want security and privacy information on product packaging, accessible without scanning. There should be an explicit requirement to include basic information on the product packaging.

account_circle
CyLab(@CyLab) 's Twitter Profile Photo

(5/6) The FCC order mentions privacy along with security, but does not include any privacy requirements. IoT labels should include basic privacy information important to consumers such as what sensors a device has and what they do with the data they collect.

account_circle
CyLab(@CyLab) 's Twitter Profile Photo

(6/6) The FCC order includes a list of required information that must be available through the label QR code. That list is missing critical security and privacy items. The FCC should revisit this list to ensure it includes key information.

account_circle