Earlier quoted context omitted.
Exactly. I don't see the situation improving until either the owner or, preferably, the manufacturer of a device that participates in a DoS attack is held partially accountable for said attack.
Well, you can't hold somebody accountable if there isn't even a label or information somewhere saying that what they are doing is dangerous.
Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
111–120 of 944 posts
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#112While the IoT security situation is out of control I doubt that regulating security updates will have any other result than radically reducing competition and innovation in the space by making it impossible to operate as a small company. It will simply push more hardware innovation out to China. Having worked in the space I came to the conclusion the only viable secure future is to adopt star topology local networks…
Fascinating! Could you elaborate?
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#113Consumers consistently vote with their wallets on this, and based on their behavior, they don't care. They will buy the cheapest devices they can find on Amazon, made somewhere in the far East, and as likely to set their house on fire as punch a gaping hole in their home computer network, when there are much better made, well-supported alternatives but they cost more. If you want to make a difference, an FCC sticker…
Personally I see it as "based on their behavior, they don't understand"
We also need far more computer/tech literacy in the education system and populace.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#114Earlier quoted context omitted.
What's stopping hobby/micro-developers from saying 'Not FCC approved, use at own risk'? I hack on ESP32 devices, I certainly have different expectations as a hobbyist and as a consumer or consultant.
> What's stopping hobby/micro-developers from saying 'Not FCC approved, use at own risk'? OP is. Or rather, he wants to make it impossible to opt out. At least that's how I interpret these two paragraphs: > The FCC recently issued a Notice of Proposed Rulemaking [2] for a cybersecurity labeling program for connected devices. If they meet certain criteria for the security of their product, manufacturers can put an FCC…
If they meet certain criteria for the security of their product, manufacturers can put an FCC cybersecurity label on it.
So if they don't, they can't put the label. That's all.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#115These rules sound like reasonable steps, upon first reading. Not sure what the downstream effects might be. Is there any thought given to cloud based devices becoming paperweight when companies behind them just stop supporting it or turn off the API? I'd like some "assurances" in place that if the company either goes out of business or decides to sunset the service, it would be required to open source (or at least ma…
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#116> The FCC recently issued a Notice of Proposed Rulemaking [2] for a cybersecurity labeling program for connected devices. That appears to me to be the wrong way to go about this, and it has specifically to do with how IoT security is a problem. The most severe case of IoT security problems we have seen were things like mass botnets, where plenty of devices of the same type were hacked and then used for things like Do…
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#117Earlier quoted context omitted.
I don't like the quoted wording. I would like it to be clearer that the RF part isn't part of the transducer, but part of the network interface.
I don't think it has to be part of the network interface. You could have an ethernet-connected device that emits RF for some non-networking purpose and I think it would still qualify.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#118Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#119Many of these devices are made in China, even if designed and sold by American companies. Nearly all contain Chinese made parts. These are network devices with sensors and various behaviors. Given the tension between USA and China, especially in the cybersecurity realm - what about making the case based on US national security (in addition to consumer protection)?
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#120I can't file because I'm not based in the US, but I'd love to see smartphones, tablets and similar devices to be covered as part of IoT in general, as they share the most important of the characteristics - the manufacturer sells a device connected to the Internet. There are multiple issues that I think need urgent regulatory attention, and the issue classes are valid for both "classic" IoT devices and phones: 1. Manu…
Re your point 4 in particular, I feel your pain -- I said "exposed public keys, expired certs" in the OP for a reason. The current item doesn't contemplate a requirement to tie these off as such, but I'd be interested to see if commenters ask for this as part of getting a stronger label.
To add on the "label" point: I don't think labels are enough, not in a world where consumers (private, commercial and governments) primarily look at the price in purchase decisions. At least a base set of legally binding requirements must be established.
ETA: I'd also love to see an exception for small scale / startups. Like < 1000 units sold per model and year. That allows quick iterations while the large offenders still have to comply.