There has been a proliferation of doomsday forecasts of the impending IoT security disaster to unfold. Many of these pundits cite the rash of recent IoT DDoS attacks and vulnerabilities. The claim is that as the number of connected and networked IoT devices attack to the internet, the exponentially greater risk there will be a complete security meltdown of these devices.
However, let's look at the numbers. How many of the recent IoT exploits were attacks on hardened or secure IoT systems? None. In fact, the attacks are against unauthenticated and insecure devices.
This means that companies are pushing devices as quickly as possible due to the fear of missing out on sales and customer market capture. This also means a period of rapid growth and development.
Though it's not far fetched to believe that the IoT devices will be security hardened. The point is that the vulnerabilities exist due to a lack of security oversight by managers and business leaders at the IoT companies. It's not the lack of secure and authenticated mechanisms. These exists.
One question is whether we will start to see the emergence of libraries, platforms, and protocols that will be shared and standardized across the industry.