News: 1638177312

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Smart things are so dumb because they take after their makers. Let's fix that

(2021/11/29)


Opinion Tech is a great leveller. You can drop [1]£50k on a shiny Tesla and £1k+ on the latest iPhone 13 Max Grunt to unlock it. But if some netops drone located half the globe away misconfigured a server, you're walking home just like a peon with a scratched-up Android and a battered Peugeot who dropped their keys down a drain.

Now, we don't know what caused the outage that outraged owners out with their Musk oxen [2]last week – Tesla doesn't care to communicate details with the press about this or anything else, really. But we do know that the best you could get if you were caught out using mankind's most advanced phone to access mankind's most advanced electric vehicle in the closing stages of 2021 was "Server Error 500."

Numeric error messages were just about OK with the [3]Sinclair ZX81 , which had the excuse of an 8 kilobyte ROM with no room for text that could be looked up in the ring-bound manual ... That was 40 years ago.

[4]

Could we have a better system today, when the cars (kind of) drive themselves and the phones can converse in conversational Catalan if we ask them? Could we use just a smidge of all that AI to tell the punters that the phone is fine, the app is fine, the problem is being experienced by some 3,000 people right now and the automated roll-back will have you back online in five minutes? Of course we could. But we don't. There's no market force, no regulator that encourages or compels.

[5]

[6]

Thus basic network error management lags other aspects of system design by decades. That's bad enough when you're puzzling things out with a full-fat browser on a system with decent diagnostics like, god help us, ping and traceroute. It is beyond terrible with embedded systems like cars, edge automation, and anything IoT. If your living room smart light starts turning itself off at random, it might as well be demonic possession as anything technical: you're not going to be able to find out.

This matters. Total absence of diagnostics isn't just a complete repudiation of the right to repair, it removes any motivation or ability to manage security. It doesn't matter how good you are, whether you spend your days in the data centre shaping traffic or infoseccing like the love child of GCHQ and the NSA. You won't get far. Take that lightbulb – any idea what protocols it's running at the top of the stack?

[7]

Chances are, if it's one of the random-brand cheapies that flood Amazon, eBay, and Banggood, it comes from Zengge, a Chinese company so obscure it has no Wikipedia entry despite flooding the globe with products by the million. The phrase "Zengge Wi-Fi protocol" yields that rarest of rare birds, a Googlewhack single result (just ruined it, sorry). The other, higher-profile internet-connected smart bulbs on the Tuya or TP-Link platforms are somewhat better known, but they're all full of home-made security running on mostly undocumented infrastructures with no discernible diagnostics.

Sure, you can approach the problem from the other end, setting up a dedicated IoT network and routing all traffic through packet capture and analysis. This is non-trivial, and making sense of what you find is even harder. And then what? It's not as if you can contact anyone who can change anything. The only responsible security approach to consumer-level IoT, from smart plugs to smart TVs, is don't touch anything that touches the internet. Not advice the world will heed.

Consumer IoT IT, in short, is the worst IT in the world, much of it resembling a productised mass of hobbyist Arduino projects. Even at the top end, a company that can make (kind of) self-driving cars and is sibling to reusable rocket ships can't keep its servers from emulating home computers with buggy BASIC. There is no way to protect consumers from its problems, no advice to give and no clear path forwards. It's the Wild West, carefully disguised as fun gadgets from the future.

[8]UK.gov emits draft IoT and smartphone security law for Parliamentary scrutiny

[9]Russia's orbital insanity is almost beyond redemption – but there's space for improvement

[10]Tech bro CEOs claim their crowns because they fix problems. Why shirk the biggest one?

[11]Please, no Moore: 'Law' that defined how chips have been made for decades has run itself into a cul-de-sac

There will be one of two outcomes: tombstone regulation, where the negative effects of such carelessness forces the imposition of [12]restrictions and standards , or an industry that learns to look after itself. The early days of the microcomputer – where the worst that could happen was that you could never make something work or, if you neglected backing up, you lost months of data – sorted itself out through finding standards and building its own tests. The magazines were full of benchmarks, compatibility reports, commendations, and warnings. IoT – where the stakes are so much higher because we're installing unknown, untestable and unreliable devices at the heart of our personal information infrastructure – needs to emulate that.

Does a device or service use inspectable, known protocols? How much does it rely on cloud services that are opaque, how much on a published architecture? What diagnostics are available, and let's see the beginning of the evolution of some standards to work towards. For when you can tell your gran to buy smart lightbulbs that have a certain score or above for technical goodness, and when the supporting infrastructure of a Tesla can be compared to that of a Nissan, then the evolution of market-driven security and reliability can begin.

[13]

The return of Tesla owners' insufferable sense of superiority will be a small price to pay. ®

Get our [14]Tech Resources



[1] https://www.theregister.com/2021/11/25/elon_musk_bust_iphone/

[2] https://www.theregister.com/2021/11/21/tesla_server_error_500_lockout/

[3] https://www.theregister.com/2018/03/06/zx81_at_37/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/edgeiot&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YaSy6vfRMvpw6p8TG2waUgAAAIA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/edgeiot&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YaSy6vfRMvpw6p8TG2waUgAAAIA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/edgeiot&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YaSy6vfRMvpw6p8TG2waUgAAAIA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/edgeiot&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YaSy6vfRMvpw6p8TG2waUgAAAIA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2021/11/25/product_security_telecoms_bill_parliament/

[9] https://www.theregister.com/2021/11/22/russias_orbital_insanity/

[10] https://www.theregister.com/2021/11/15/tech_must_help_save_planet/

[11] https://www.theregister.com/2021/08/05/moores_law_what_next/

[12] https://www.theregister.com/2021/11/25/product_security_telecoms_bill_parliament/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/edgeiot&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YaSy6vfRMvpw6p8TG2waUgAAAIA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://whitepapers.theregister.com/



What are error messages for?

Pete 2

> "Server Error 500."

ISTM there are two issues here.

The first is to appease irate users who have made the basic error of relying on technology that still needs another 5 minutes under the grill before it will be ready for everyday use by everyday users.

The second is that the function of an error message is to communicate state in an accurate (top priority) and concise form. Such that those in the position and with the ability to resolve it receive the information they require.

In the second case short numerical error messages do the job very well. Provided the error codes are unique and well enough defined that a single code points to a single cause of failure (and from there, hopefully a well defined fix). Their nature also makes it easy for a non-techy to report the exact message to those who need to know. Often without too much prompting.

However, they also provide a perfect platform for tech-haters to criticise systems for "gobbledygook" as their meaning is obscure to the average person. However, would a longer message, along the lines of "I'm so sorry but the computer is completely buggered up at the moment. We will be restoring normality just as soon as we are sure what is normal" be any more helpful than "Oooops, sorriy", or just :( ?

Re: What are error messages for?

ComputerSays_noAbsolutelyNo

Numerical error codes can of course be consise and precise indicators of status, but

1, they need to be sufficiently unique to actually make sense

2. they need to be documented somewhere, and this somewhere should not be secret knowledge of the illumiated few

While it would be nice to see IoT IT adhere to these points, not even plain IT follows them.

Trouble-shooting IT errors, which provide a numerical error, should lead via the first google hit to a knowledge base of the respective vendor which lists all error codes and the conditions which trigger them.

What you get instead is: you google "product error X", and you get hits for "product error Y", and if you ever find some info on "error X", you read that "error X" may be caused by A, B or C.

Yeah, thanks for nothing. I'll get my coat.

Re: What are error messages for?

Boris the Cockroach

Quote

"technology that still needs another 5 minutes under the grill before it will be ready for everyday use by everyday users."

I would say that a hell of a lot of that technology needs more than 5 minutes under that grill

5 days would be closer.. along with the system designers and the marketeers who insist we need the latest and shiniest.

Lets see... in these days of systems on a chip , is there any need for your phone app to talk to a central server, which then sends commands back to your lightbulbs to dim down 50%? hell no.

The phone app should be paired with the SOC running your lights... send a command to that and your lights dim... without the need for anything to leave your house and get filed away/sorted and sold to a 3rd company making curtains.

Or am I just old and grumpy?

"Consumer IoT IT, in short, is the worst IT in the world"

Mike 137

The worst, probably because in most cases the hardware/firmware is largely non-profit making. It's the data stream that's the source of revenue. Consequently the kit is 'made to a price'.

Anonymous Coward

As a techie, I don't think "500 server error" is a bad message, because it gives me information that I can use in troubleshooting. I know what it means and if I didn't then I could look it up.

It's far better than the modern windows favourite of "We had a problem". What kind of problem? Disk? Network? Null pointer? Access Violation? No fucking useful information whatsoever. I just have to guess what it might be.

It isn't any better than the blatantly misleading "You may not have permission to access this resource", which has never in history been triggered by a lack of permissions.

You rarely need a java style full stack trace, but you do need some accurate and meaningful technical information to start troubleshooting a problem.

Doctor Syntax

If Server error 500 is a catch-all for errors that should have been caught and maybe automaticelly recovered some way back along the chain it won't help you very much.

"Server error 500"

Dan 55

I'm not sure what a plain-English replacement for that error code would look like.

Well I am, as it's a consumer-facing product, it would be something along the lines of, "Hey there, something's not quite right :(, why dontcha try again later when it's right. :)" with a whimsical doodle next to it.

Fucking IT.

Re: "Server error 500"

DJV

Maybe it should be along the lines of:

Error code for techies: Server error 500

Translation for normal humans*: Hey, it's not my fault! Me (the bit you're holding in your hand) is working fine. I'm trying to talk to another bit a long way away out on teh interwebs. Teh interwebs seem to be working fine as I am managing to shout all the way to other bit. But the other bit isn't talking back in a way that I can understand. Until it does there's not a lot I can do at my end. I suspect coffee is called for at your end. If you're not at home should I try to find the nearest coffee shop (within walking distance**)? While you enjoy your coffee I will keep trying to talk to the other bit and I will ding at you when things are all happy again.

Error messages like this will certainly not add to the app bloat much, well maybe a little (ok, a lot then).

(* yes, I know what that is implying! :)

(** added if the thing the user is trying to get working is a Tesla***)

(*** other electric vehicles as amazing**** as Teslas are available)

(**** stop laughing)

It is like saying that for the cause of peace, God and the Devil will
have a high-level meeting.
-- Rev. Carl McIntire, on Nixon's China trip