Hacker News new | ask | show | jobs
by exelius 3020 days ago
I thought Apple required HomeKit devices to go through a certification process that includes an audit of device security controls (things like secret management, crypto, default passwords, etc) — and very few of these low-cost IoT devices worry about security.

Apple won’t certify them, but there’s not yet a mass market for secure IoT devices (which would necessarily cost more due to the extra engineering required). It’s a bit of a chicken-and-egg problem.