Earlier quoted context omitted.
Consumer's power is not the same as FCC's
Indeed. And that's good.
Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
191–200 of 944 posts
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#192FWIW, seeing a security compliance label on an IoT product wouldn't mean anything to me as a consumer. There is no such thing as computer security in 2023, and there are no hints that security will exist at any point on the horizon. Even the biggest names in the field cannot put out secure products. Products from well-meaning manufacturers are going to be absolutely riddled with security problems, and putting a stick…
I understand your skepticism. That's why I want to see the label functioning as something like an enforceable representation to consumers. If someone wants to sell brick-proof glass, and get a sticker from the US Government saying so, it better be brick-proof.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#193IoT devices need regulatory standardization w.r.t a few things: 1. software stack – big fat "firmware" should not exist. Entire stack should be upgradable safely, securely and frequently during its official supported lifetime and should be open-sourced for owner's own upgrades past end of life. For this, the hardware stack needs some amount of standards compliance. 2. Vendor should clearly declare/advertise the perio…
Ideally the user should have to specifically consent to inbound communication on an instance-by-instance basis, even from the manufacturer. There's many cases where forced updates are triggered that change/limit functionality unexpectedly. There's numerous anecdotes of people's devices being required to update to be used while they have some pressing need to use it.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#194Regulation to require a certain period of security updates doesn't seem useful to me. It's very easy to send out a "security update" that doesn't actually improve security. You can send out an ad to all your users saying "You should upgrade now to our newest product!" and call it a security update. Requiring security updates may end up just requiring companies to spam their users with a certain amount of marketing ma…
You could regulate they have to patch any outstanding CVEs for their device/firmware but enforceability might be difficult.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#195From the speech: > Wi-Fi deauthentication attacks, which can render useless every Wi-Fi network in an area, can be carried out by a single device with a Wi-Fi antenna. Is the prevention of such attacks within the mandate of the FCC (so long as all other relevant RF parameters are adhered to in the device)? I understood that unlicensed ISM users must not cause interference to licensed users, and they must be tolerant…
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#196FWIW, seeing a security compliance label on an IoT product wouldn't mean anything to me as a consumer. There is no such thing as computer security in 2023, and there are no hints that security will exist at any point on the horizon. Even the biggest names in the field cannot put out secure products. Products from well-meaning manufacturers are going to be absolutely riddled with security problems, and putting a stick…
> There is no such thing as computer security in 2023 This is absurd. Even the passive basics like relying on your free email provider's filtering and running Windows Defender is going to stop a huge number of attacks. If you're expecting perfect security, you'll be disappointed -- but we can't declare complete bankruptcy.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#197Has much consideration been given to labeling when a third party cloud or paid service is required to use the device? As somebody who uses IoT devices "locally" on my private network, I want to know my data will stay local and protected. The recent issues with Eufy doorbells claiming to be under local control [and encrypting data], but actually sending data to the cloud stands out to me as an example where labeling a…
Right now, the actual requirements for a label are totally up for grabs. This would make for a good public comment, in my opinion.
For context, I've thought about commenting on issues in the past, but especially on the heels of the fake comments regarding net neutrality, for lack of a better way to put it I'm left feeling outgunned against such sophisticated lawyers and companies. This may be a little paranoid, but from a risk perspective I also worry about having my name attached to comments that go against the interests of large companies which dominate the marketplace. I also have hesitation about identity theft and uncertainty about the process.
Again, thank you for bring the conversation home, so to speak. I'll look at the process again.
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#198How about requiring devices to accept alternate, Free Software firmware, from the upstream provider? At the very least, it should be possible after some time period of no updates or insecurity, but a blanket requirement is less susceptible to games. Probably the best thing to happen to wireless routers is OpenWRT and the other descendents of the WRT firmware.
Openwrt is not the best example. Community sucks, some routers are full of bugs and the security is not great either. In general even if I like open devices and having the option to use my own software, this is not a solution for most of the consumers. It is not a solution even for the enthusiast that know how to flash their own firmware. Because even if they may do it a few times initially, eventually they stop doin…
there are a lot of open and closed firmware projects building upon openwrt
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#199Regulation to require a certain period of security updates doesn't seem useful to me. It's very easy to send out a "security update" that doesn't actually improve security. You can send out an ad to all your users saying "You should upgrade now to our newest product!" and call it a security update. Requiring security updates may end up just requiring companies to spam their users with a certain amount of marketing ma…
You could regulate they have to patch any outstanding CVEs for their device/firmware but enforceability might be difficult.
[1] https://daniel.haxx.se/blog/2023/08/26/cve-2020-19909-is-eve... [2] https://www.sqlite.org/cves.html
Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
#200A few examples-
- internet enabled lights should say if they light up if no internet is available.
- internet enabled exercise equipment should say what is operational and what is not when there is no internet.
- automobiles should provide thorough documentation about what does not work and what does work when there is no internet