
“This report concludes that current market incentives do too little to promote security in internet-connected products, corroborating a longstanding concern I have had with the burgeoning market of Internet of Things (IoT) devices. The failure of these market forces to reward security over cost or convenience has led to devastating DDoS attacks (like the Mirai botnet) that contribute to internet-wide insecurity to this day.
“I am pleased to see the Departments of Commerce and Homeland Security acknowledge that the federal government should lead by example by requiring the acquisition of far more secure and resilient services and products; Congress should take the next step and pass bipartisan legislation I have introduced with Sen. Gardner that would set minimum security requirements for federal procurements of IoT devices.”