USENIX Security2024Top-tier venue
"Belt and suspenders" or "just red tape"?: Investigating Early Artifacts and User Perceptions of IoT App Security Certification
Prianka Mandal, Amit Seal Ami, Victor Olaiya, Sayyed Hadi Razmjo, Adwait Nadkarni
Abstract
As IoT security regulations and standards emerge, the industry has begun adopting the traditional enforcement model for software compliance to the IoT domain, wherein Commercially Licensed Evaluation Facilities (CLEFs) certify vendor products on behalf of regulators (and in turn consumers). Since IoT standards are in their formative stages, we investigate a simple but timely question: does the traditional model work for IoT security, and more importantly, does it work as well as consumers expect it to? This paper investigates the initial artifacts resultant from IoT compliance certification, and user perceptions of compliance, in the context of certified mobile-IoT apps, i.e., critical companion and automation apps that expose an important IoT attack surface, with a focus on three key questions: (1) are certified IoT products vulnerable?, (2) are vulnerable-but-certified products non-compliant?, and finally, (3) how do consumers perceive compliance enforcement? Our systematic analysis of 11 mobile-IoT apps certified by IOXT, along with an analysis of 5 popular compliance standards, and a user study with 173 users, together yield 17 key findings. We find significant vulnerabilities that indicate gaps in certification, but which do not violate the standards due to ambiguity and discretionary language. Further, these vulnerabilities contrast with the overwhelming trust that users place in compliance certification and certified apps. We conclude with a discussion on future directions towards a "belt and suspenders" scenario of effective assurance that most users desire, from the status quo of "just red tape", through objective checks and balances that empower the regulators and consumers to reform compliance enforcement for IoT.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- "We can't Allow IoT Vendors to Pass off all Such Liability to the Consumer": Investigating the U.S. Legal Perspectives on Liability for IoT Product SecurityPrianka Mandal, Amit Seal Ami, Iria Giuffrida, Daniel Shin et al.S&P 2025
- "We can't Change it Overnight": Understanding Industry Perspectives on IoT Product Security Compliance and CertificationPrianka Mandal, Adwait NadkarniS&P 2025
Builds on14
- SmartAuth: User-Centered Authorization for the Internet of ThingsYuan Tian, Nan Zhang, Yue-Hsun Lin, XiaoFeng Wang et al.USENIX Security 2017 · 231 citations
- Ask the Experts: What Should Be on an IoT Privacy and Security Label?Pardis Emami Naeini, Yuvraj Agarwal, Lorrie Faith Cranor, Hanan HibshiS&P 2020 · 195 citations
- PolicyLint: Investigating Internal Privacy Policy Contradictions on Google PlayBenjamin Andow, Samin Yaseer Mahmud, Wenyu Wang, Justin Whitaker et al.USENIX Security 2019 · 185 citations
- CryptoGuard: High Precision Detection of Cryptographic Vulnerabilities in Massive-sized Java ProjectsSazzadur Rahaman, Ya Xiao, Sharmin Afrose, Fahad Shaon et al.CCS 2019 · 159 citations
- Looking from the Mirror: Evaluating IoT Device Security through Mobile Companion AppsXueqiang Wang, Yuqiong Sun, Susanta Nanda, XiaoFeng WangUSENIX Security 2019 · 65 citations
Related papers
- Security Update Labels: Establishing Economic Incentives for Security Patching of IoT Consumer ProductsPhilipp Morgner, Christoph Mai, Nicole Koschate-Fischer, Felix C. Freiling et al.S&P 2020 · 41 citations
- Understanding IoT Security from a Market-Scale PerspectiveXin Jin, Sunil Manandhar, Kaushal Kafle, Zhiqiang Lin et al.CCS 2022 · 30 citations
- P-Verifier: Understanding and Mitigating Security Risks in Cloud-based IoT Access PoliciesZe Jin, Luyi Xing, Yiwei Fang, Yan Jia et al.CCS 2022 · 19 citations
- IoTGuard: Dynamic Enforcement of Security and Safety Policy in Commodity IoTZ. Berkay Celik, Gang Tan, Patrick D. McDanielNDSS 2019 · 254 citations
- Measuring Up to (Reasonable) Consumer Expectations: Providing an Empirical Basis for Holding IoT Manufacturers Legally ResponsibleLorenz Kustosch, Carlos Gañán, Mattis van 't Schip, Michel van Eeten et al.USENIX Security 2023
