{"id":{"repo_id":"mit","oai_identifier":"oai:dspace.mit.edu:1721.1/111231"},"canonical_url":"https://search.dev.ndltd.org/etd/mit/oai:dspace.mit.edu:1721.1/111231","repository":{"repo_id":"mit","name":"MIT","base_url":"https://dspace.mit.edu/oai/request"},"display":{"title":"Dead reckoning : where we stand on privacy and security controls for the Internet of Things","abstract":"This thesis provides an analysis of privacy and security controls for internet-connected data-driven systems, known as the Internet of Things (IoT). The grounding theory is that numerous pre-existing privacy and security control methods -- not necessarily crafted for IoT -- will bear on the future of IoT privacy and security. This thesis covers fifteen case studies across six different control categories: Individual Choice, Command and Control Regulations, Operational Standards, Technical Standards, Compliance Frameworks, and Federal Authorities. These case studies reveal major deficiencies in current IoT privacy and security controls. IoT privacy and security controls lack a domain or contextual-use focus. Further, most current controls also fail to specify the risks or harms they intend to resolve. Therefore, the current IoT privacy and security controls induce a significant privacy and security market failure. This market failure is evident in recent IoT privacy and security events such as the Federal Trade Commission's cases against the IoT system developers TRENDnet and D-Link. I define three necessary paradigm shifts needed to improve IoT privacy and security controls. I also recommend a specific research endeavor to develop domain-, risk-, and harms-centric privacy and security standards. The realization of these paradigm shifts, and the products from this research endeavor, will navigate the IoT ecosystem towards more effective privacy and security control.","abstract_html":"This thesis provides an analysis of privacy and security controls for internet-connected data-driven systems, known as the Internet of Things (IoT). The grounding theory is that numerous pre-existing privacy and security control methods -- not necessarily crafted for IoT -- will bear on the future of IoT privacy and security. This thesis covers fifteen case studies across six different control categories: Individual Choice, Command and Control Regulations, Operational Standards, Technical Standards, Compliance Frameworks, and Federal Authorities. These case studies reveal major deficiencies in current IoT privacy and security controls. IoT privacy and security controls lack a domain or contextual-use focus. Further, most current controls also fail to specify the risks or harms they intend to resolve. Therefore, the current IoT privacy and security controls induce a significant privacy and security market failure. This market failure is evident in recent IoT privacy and security events such as the Federal Trade Commission&#x27;s cases against the IoT system developers TRENDnet and D-Link. I define three necessary paradigm shifts needed to improve IoT privacy and security controls. I also recommend a specific research endeavor to develop domain-, risk-, and harms-centric privacy and security standards. The realization of these paradigm shifts, and the products from this research endeavor, will navigate the IoT ecosystem towards more effective privacy and security control.","abstract_has_math":false,"creators":["Karpf, Brandon Allan"],"institution":"Massachusetts Institute of Technology","degree_name":null,"degree_level":null,"degree_discipline":null,"degree_department":"Massachusetts Institute of Technology. Institute for Data, Systems, and Society.","school":null,"contributors":[],"advisors":["David D. Clark."],"committee_chairs":[],"committee_members":[],"year":2017,"date_issued":"2017","date_published":"2017","updated_at":"2026-07-22T22:20:53Z","subjects":["Institute for Data, Systems, and Society.","Engineering Systems Division.","Technology and Policy Program."],"languages":["eng"],"rights":["MIT theses are protected by copyright. They may be viewed, downloaded, or printed from this source but further reproduction or distribution in any format is prohibited without written permission."],"rights_urls":["http://dspace.mit.edu/handle/1721.1/7582"],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/1721.1/111231","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["David D. Clark."]},{"key":"dc:contributor.department","label":"Department","values":["Massachusetts Institute of Technology. Institute for Data, Systems, and Society.","Massachusetts Institute of Technology. Engineering Systems Division.","Technology and Policy Program."]},{"key":"dc:contributor.other","label":"Dc Contributor Other","values":["Technology and Policy Program."]},{"key":"dc:creator","label":"Author","values":["Karpf, Brandon Allan"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2017-09-15T14:20:24Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2017-09-15T14:20:24Z"]},{"key":"dc:date.issued","label":"Date","values":["2017"]},{"key":"dc:publisher","label":"Institution","values":["Massachusetts Institute of Technology"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Institute for Data, Systems, and Society.","Engineering Systems Division.","Technology and Policy Program."]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["eng"]},{"key":"dc:rights","label":"Dc Rights","values":["MIT theses are protected by copyright. They may be viewed, downloaded, or printed from this source but further reproduction or distribution in any format is prohibited without written permission."]},{"key":"dc:rights.uri","label":"Rights URI","values":["http://dspace.mit.edu/handle/1721.1/7582"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["http://hdl.handle.net/1721.1/111231"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["Thesis: S.M. in Technology and Policy, Massachusetts Institute of Technology, School of Engineering, Institute for Data, Systems, and Society, Technology and Policy Program, 2017.","This electronic version was submitted by the student author. The certified thesis is available in the Institute Archives and Special Collections.","Cataloged from student-submitted PDF version of thesis.","Includes bibliographical references (pages 201-218)."]},{"key":"dc:description.abstract","label":"Abstract","values":["This thesis provides an analysis of privacy and security controls for internet-connected data-driven systems, known as the Internet of Things (IoT). The grounding theory is that numerous pre-existing privacy and security control methods -- not necessarily crafted for IoT -- will bear on the future of IoT privacy and security. This thesis covers fifteen case studies across six different control categories: Individual Choice, Command and Control Regulations, Operational Standards, Technical Standards, Compliance Frameworks, and Federal Authorities. These case studies reveal major deficiencies in current IoT privacy and security controls. IoT privacy and security controls lack a domain or contextual-use focus. Further, most current controls also fail to specify the risks or harms they intend to resolve. Therefore, the current IoT privacy and security controls induce a significant privacy and security market failure. This market failure is evident in recent IoT privacy and security events such as the Federal Trade Commission's cases against the IoT system developers TRENDnet and D-Link. I define three necessary paradigm shifts needed to improve IoT privacy and security controls. I also recommend a specific research endeavor to develop domain-, risk-, and harms-centric privacy and security standards. The realization of these paradigm shifts, and the products from this research endeavor, will navigate the IoT ecosystem towards more effective privacy and security control."]},{"key":"dc:description.degree","label":"Dc Description Degree","values":["S.M. in Technology and Policy"]},{"key":"dc:title","label":"Title","values":["Dead reckoning : where we stand on privacy and security controls for the Internet of Things"]}]}],"canonical_facts":{"dc:contributor.advisor":["David D. Clark."],"dc:contributor.department":["Massachusetts Institute of Technology. Institute for Data, Systems, and Society.","Massachusetts Institute of Technology. Engineering Systems Division.","Technology and Policy Program."],"dc:contributor.other":["Technology and Policy Program."],"dc:creator":["Karpf, Brandon Allan"],"dc:date.accessioned":["2017-09-15T14:20:24Z"],"dc:date.available":["2017-09-15T14:20:24Z"],"dc:date.issued":["2017"],"dc:description":["Thesis: S.M. in Technology and Policy, Massachusetts Institute of Technology, School of Engineering, Institute for Data, Systems, and Society, Technology and Policy Program, 2017.","This electronic version was submitted by the student author. The certified thesis is available in the Institute Archives and Special Collections.","Cataloged from student-submitted PDF version of thesis.","Includes bibliographical references (pages 201-218)."],"dc:description.abstract":["This thesis provides an analysis of privacy and security controls for internet-connected data-driven systems, known as the Internet of Things (IoT). The grounding theory is that numerous pre-existing privacy and security control methods -- not necessarily crafted for IoT -- will bear on the future of IoT privacy and security. This thesis covers fifteen case studies across six different control categories: Individual Choice, Command and Control Regulations, Operational Standards, Technical Standards, Compliance Frameworks, and Federal Authorities. These case studies reveal major deficiencies in current IoT privacy and security controls. IoT privacy and security controls lack a domain or contextual-use focus. Further, most current controls also fail to specify the risks or harms they intend to resolve. Therefore, the current IoT privacy and security controls induce a significant privacy and security market failure. This market failure is evident in recent IoT privacy and security events such as the Federal Trade Commission's cases against the IoT system developers TRENDnet and D-Link. I define three necessary paradigm shifts needed to improve IoT privacy and security controls. I also recommend a specific research endeavor to develop domain-, risk-, and harms-centric privacy and security standards. The realization of these paradigm shifts, and the products from this research endeavor, will navigate the IoT ecosystem towards more effective privacy and security control."],"dc:description.degree":["S.M. in Technology and Policy"],"dc:identifier.uri":["http://hdl.handle.net/1721.1/111231"],"dc:language.iso":["eng"],"dc:publisher":["Massachusetts Institute of Technology"],"dc:rights":["MIT theses are protected by copyright. They may be viewed, downloaded, or printed from this source but further reproduction or distribution in any format is prohibited without written permission."],"dc:rights.uri":["http://dspace.mit.edu/handle/1721.1/7582"],"dc:subject":["Institute for Data, Systems, and Society.","Engineering Systems Division.","Technology and Policy Program."],"dc:title":["Dead reckoning : where we stand on privacy and security controls for the Internet of Things"],"dc:type":["Thesis"]},"updated_at":"2026-07-22T22:20:53Z"}