Live data from Hacker News

Viewing profile — MarcoPerazaFCC

MarcoPerazaFCC

HN member
Joined
Fri, Sep 01, 2023, 9:18 PM UTC
HN karma
129
Public activity
31 items

About MarcoPerazaFCC

No profile information was provided.

Recent public activity

  1. comment
  2. comment
    Comment #37400096

    Thanks for the thoughtful reply. I encourage you to file an official comment with your ideas.

  3. comment
    Comment #37398349

    Thank you for this detailed feedback. In the long-run, it's worth asking whether a business that doesn't make money once externalities have been internalized is a business worth ha…

  4. comment
    Comment #37398251

    One my favorite IoT botnet scenarios is an attacker taking control of thousands of ovens/air conditions/other high-wattage devices and using them to cause power outages. https://ww…

  5. comment
    Comment #37398126

    Good question. There's some discussion in this thread https://news.ycombinator.com/item?id=37395218

  6. comment
    Comment #37398100

    I think you're right that it would be difficult for the FCC to precisely define exactly when security updates are required. This is a problem in law generally, one that is usually …

  7. comment
    Comment #37398091

    It's a voluntary label, so it's open to competition from other standard-setting organizations. When it comes to mandatory regulations generally, our office thinks that broad standa…

  8. comment
    Comment #37397656

    I think you're right that it would be difficult for the FCC to precisely define exactly when security updates are required. This is a problem in law generally, one that is usually …

  9. comment
    Comment #37397640

    I think if the box says updates until the beginning of 2025, and they've stopped providing updates before then, you have a pretty good contract lawsuit against them. You'd have to …

  10. comment
    Comment #37397527

    These are all great points and maybe a good reason why a voluntary program like this is the way to start, so a higher-tier of secure products can begin to emerge. We would also lov…

  11. comment
    Comment #37397461

    Thanks for this thoughtful feedback. I encourage you to file an official comment, especially regarding end-user control of update timing. Maybe my response here https://news.ycombi…

  12. comment
    Comment #37397391

    This will be a completely optional program. And the proposal is that even for participants of the program, they just have to disclose the update period, whatever it may be (could b…

  13. comment
    Comment #37397086

    This is something that has us worried too. The FCC took some action on this issue last year by outright banning equipment from certain companies (e.g. Huawei), but we haven't even …

  14. comment
    Comment #37396768

    I encourage you to file a comment suggesting this. It's actually not irrelevant. The FCC is free to decide that the label (which can include a QR code linking to more information) …

  15. comment
    Comment #37396556

    Hi, the short of it is that I decided to go to law school and then looked for jobs focusing on cybersecurity. If you're interested in jumping over to law, I'm happy to talk about i…

  16. comment
    Comment #37396434

    This is being proposed as a completely voluntary program. No need to participate in it if you don't want an FCC cybersecurity label on your product.

  17. comment
    Comment #37395401

    If you think stronger action is needed, please share it through an official comment. Even if we don't do what you suggest, thoughtful comments really do influence the rulemaking pr…

  18. comment
    Comment #37395361

    > I've purchased equipment, new in the box, after the mfg had discontinued support. Exactly the kind of thing that sounds crazy but still happens. > 1. Final date the manufacturer …

  19. comment
    Comment #37395291

    The general rule in tort is that you need physical injury or physical destruction of property to sustain a lawsuit. There's exceptions at the edges of that, but you basically can't…

  20. comment
    Comment #37395218

    Good question. The Notice of Proposed Rulemaking has a Legal Authority section that discusses this issue https://www.fcc.gov/document/fcc-proposes-cybersecurity-labe... . I also to…

  21. comment
    Comment #37395088

    Maybe the presence or absence of this capability could be something disclosed on the label? It's an idea worth thinking about. I encourage you to file a comment with your thoughts …

  22. comment
    Comment #37394935

    Thank you for these thoughtful points. Some relevant responses from other threads: From https://news.ycombinator.com/item?id=37394188 : I think you're right that it would be diffic…

  23. comment
    Comment #37394793

    > And since this is HN - there is a startup hidden in the midst of all of this: an enterprise-grade IoT OS that "does security right." Sell to the device manufacturers, allow them …

  24. comment
    Comment #37394707

    These could be great suggestions for the criteria a product must meet to quality for a label. I encourage you to file an official comment with your thoughts.

  25. comment