Live data from Hacker News

Viewing profile — SimingtonFCC

SimingtonFCC

HN member
Joined
Thu, Dec 15, 2022, 6:26 PM UTC
HN karma
1,393
Public activity
37 items

About SimingtonFCC

No profile information was provided.

Recent public activity

  1. comment
    Comment #37398608

    I would love to see frank discussion on the record of consumer-grade vs infrastructure-grade practices and what label(s) would be appropriate for each! It’s not lost on me either t…

  2. comment
    Comment #37397375

    Hi and thanks for commenting. My concern with this topic is motivated in part by the AcidRain family of energy infrastructure attacks and the larger questions they raise about infr…

  3. comment
    Comment #37397295

    Thank you so much everyone for the interesting, high-quality discussion so far. My team and I are looking forward to continuing to engage with you for at least a few more hours. Ju…

  4. comment
    Comment #37396513

    Thanks again -- will review both links (especially the latter!) The FCC hasn't traditionally been a cybersecurity agency and will, most likely, never really be one; however, we can…

  5. comment
    Comment #37396450

    Thanks! Sorry for any lack of clarity. My initial draft was way over the character limit and I had to cut a lot prior to posting. Thanks for highlighting the relevant language and …

  6. comment
    Comment #37395891

    Flash ROM comment noted. It would be bad if getting a label required a manufacturer to do something objectively anti-user.

  7. comment
    Comment #37395882

    Comments against push updates and highlighting industrial applications would be a very important part of record development. I would expect industrial buyers to have very different…

  8. comment
    Comment #37395646

    Really appreciate your kind words and the effort required in getting your arms around so much material so quickly. it would be really useful if there were a TLDR version I agree; I…

  9. comment
    Comment #37395516

    Thanks for raising this. I support the law addressing this issue and would also support Commission action on this.

  10. comment
    Comment #37395417

    Thanks for your response! This would be an excellent comment on the record, and implanted devices are a particularly compelling example considering cases such as Second Sight.

  11. comment
    Comment #37395386

    It might help to explain how that works - how do public comments influence things? The FCC conducts notice-and-comment rulemaking and is accountable to a public interest standard. …

  12. comment
    Comment #37395233

    I would suggest to my peers, that the links you gave are "official channels," and are probably what you really want, as opposed to a rather rambling thread of comments. I sort of w…

  13. comment
    Comment #37395150

    High-quality comment. Thanks very much! I'll read your filing and think about it. But also, it's a great example of impactful public FCC commentary. I hope your work inspires other…

  14. comment
    Comment #37394973

    This would make for a fine comment on the record. It would be great to have suggestions about pros and cons of government, court, third-party and other audit means.

  15. comment
    Comment #37394952

    I don't know about a mandatory update regulation -- one way or the other, that isn't on the table right now. I would love extensive discussion on the record, however, of the costs …

  16. comment
    Comment #37394941

    Completely agree! The public record in this case is going to be what agencies and industry looks to, far more than whatever I might happen to personally believe. I'm going to get a…

  17. comment
    Comment #37394110

    Thanks for yours! It depends how much the labels shape behavior. I'm envisioning a "high-tier" label that says that risks X, Y and Z have been addressed by M means and that, e.g., …

  18. comment
    Comment #37394023

    I understand your skepticism. That's why I want to see the label functioning as something like an enforceable representation to consumers. If someone wants to sell brick-proof glas…

  19. comment
    Comment #37394002

    There are a couple of NIST papers on specifics for labels: https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.02042022-2.... https://www.nist.gov/itl/executive-order-14028-improving-…

  20. comment
    Comment #37393910

    Right now, the actual requirements for a label are totally up for grabs. This would make for a good public comment, in my opinion.

  21. comment
    Comment #37393896

    manufacturers are simply never going to be incentivized to take security seriously I worry about this too, and it's one thing when it's a camera but another when it's a car, or ele…

  22. comment
    Comment #37393768

    My two cents is that this would be an excellent comment on the record -- I'd love a discussion at the level of defining security risks to be part of the official federal commentary…

  23. comment
    Comment #37393662

    Sorry for any confusion. The relevant language: If they meet certain criteria for the security of their product, manufacturers can put an FCC cybersecurity label on it. So if they …

  24. comment
    Comment #37393645

    Re your point 4 in particular, I feel your pain -- I said "exposed public keys, expired certs" in the OP for a reason. The current item doesn't contemplate a requirement to tie the…

  25. comment
    Comment #37393594

    None taken, of course. Several people in this thread have made this point, and it's a very reasonable one. The current framework is 100% voluntary for what amounts to a marketing l…