Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

281–290 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#281
post #208
post #93

One thing that regulators need to be very careful about is how "security updates" are defined, and exactly what manufacturer obligations for issuing security updates should be. CVEs are a notoriously terrible representation of actual security risks, so a measure like "manufacturer must issue new releases that include any released patches for CVEs with a severity rating greater than 9" would be a clear non-starter. Th…

I'm curious about your thoughts on balancing the damage of another Mirai with the damage of another SolarWinds. A regulation where every IoT device must accept a signed OTA update would make update servers an extremely valuable target for supply chain compromises. On the one hand, without updates, a world of IoT devices will inevitably get infected slowly and permanently (as long as they're physically active). But on…

I don't know about a mandatory update regulation -- one way or the other, that isn't on the table right now. I would love extensive discussion on the record, however, of the costs and benefits of requiring updates to get the label.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#282

With all due respect, I think the market should address this. Like UL Approval from Underwriters Laboratories, players in the market can submit their products to an organization that vets their security and sets standards about updates, product lifetimes, security incident response time commitments etc to obtain their seal of approval. Perhaps the seal has grade levels to indicate the vendor's commitment to security.…

Not a bad idea at all. However, if they are not doing this already voluntarily, they'll need to be persuaded. Perhaps a role for the FCC.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#283

With all due respect, I think the market should address this. Like UL Approval from Underwriters Laboratories, players in the market can submit their products to an organization that vets their security and sets standards about updates, product lifetimes, security incident response time commitments etc to obtain their seal of approval. Perhaps the seal has grade levels to indicate the vendor's commitment to security.…

This would make for a fine comment on the record. It would be great to have suggestions about pros and cons of government, court, third-party and other audit means.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#284
post #93

One thing that regulators need to be very careful about is how "security updates" are defined, and exactly what manufacturer obligations for issuing security updates should be. CVEs are a notoriously terrible representation of actual security risks, so a measure like "manufacturer must issue new releases that include any released patches for CVEs with a severity rating greater than 9" would be a clear non-starter. Th…

While I acknowledge that CVE scoring of risk can be inconsistent and sometimes wildly wrong, what would you suggest in its place?

just go by past incidents. Quite often it is not software vuln that enables hacker's attack - it is insecure default config that user never changes and manufacturer supplies same default user/pw with each device.

also insecure backdoors left by developers for debug purposes (or is it really debug or maybe espionage?)

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#285
This is a great idea. The Philips Hue hub situation is a great case study that many are probably familiar with where the support ended for the first version of the IoT hub much sooner than many consumers were expecting. It's like a more acute and malicious form of planned obsolescence.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#286
I went to an EFF event where there was a guy from Sling Media (Slingbox, remember them?) who said the one point that overrides all others in importance, which he learned from EFF, is that updates should never be force pushed.

Designing a device to accept force pushed updates opens non-addressable security holes by giving a mechanism that will allow political players, acquiring companies, or pretty much anyone with an angle, to use the legal system to exert any control and conduct any abuse they can get away with.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#287
Data collection is another point - customers need to know if their personal data, video streams are being collected and stores somewhere?

like video camera streams, voice audio, images, etc - are they being used to train AI models for some object recognition of some sort?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#288
post #46

There’s some great recommendations in this thread but I just want to thank you for engaging with this community to solicit opinions from the trenches. This is really meaningful to most of us who see the regulations in our lives as something far away that we can’t influence. Another reminder for everyone that while you likely can’t influence something like a presidential election on your own, you can influence many ot…

Thanks! I am thrilled that so many people are participating. The FCC is going to need a lot of this community's input over the next few years as more and more devices go online.

The biggest problem isn't even new regulations. The liability for violation always tends to be a rounding error to profits. Then, even if there are teeth, there is no money for enforcement which makes it all pointless.

Look at how the FTC and SEC have completely failed us in the 21st century. Better regulations would matter if we ever bothered to enforce the ones we already have.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#289

Awesome! Thanks for engaging, where the rubber meets the road! Hopefully, you are also looking into other venues, as well. HN has a great group of folks that represent some of the most cutting-edge tech, but IT runs on Java 8[0]. [0] https://news.ycombinator.com/item?id=19877916

Thanks for participating! After this thread winds down, I and my team are going to comb through it for suggestions and take as many as we can. We're also looking into other venues to engage directly with cybersecurity professionals. But please feel free to comment on the record as well -- a robust and detailed record is worth a lot more than whatever I can do individually.

I think that you'll get a lot of feedback.

I would suggest to my peers, that the links you gave are "official channels," and are probably what you really want, as opposed to a rather rambling thread of comments.

But for me, you just get a rambling comment.

I made my career on devices. In particular digital scanners and cameras.

I worked for a company that was about as tinfoil as you could get, and they supported devices long past their sell-by date.

But I also know that my company was an outlier. They sold premium equipment, at a premium price. They were an "old-fashioned" Japanese corporation, and had a basic mindset of keeping the customer's workflow in the center of the screen.

I think IoT security is a huge issue, and I think that the solution could be that there are standard, open-source, open-license, free-to-use packages; maybe written in languages like C, that could be offered to the industry. These could enforce low-level compliance with security standards.

Oh, and keep the TLAs out of it. They would really like to put a bit of "extra spice" in something like that.

That said, I know that it will never happen. There's a gazillion issues.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#290
post #93

One thing that regulators need to be very careful about is how "security updates" are defined, and exactly what manufacturer obligations for issuing security updates should be. CVEs are a notoriously terrible representation of actual security risks, so a measure like "manufacturer must issue new releases that include any released patches for CVEs with a severity rating greater than 9" would be a clear non-starter. Th…

> There are also often practical issues related to security patching embedded devices: for example, a downstream supplier's driver can make it impossible to upgrade a kernel unless/until the supplier provides a fix. Of course, strong regulation here could help to drive bad practices like that out of the industry, but I'm not going to hold my breath on that one. The effect of regulation like this would make it harder…

Then fire your shitty vendor or refund your customers.

Nothing will change unless everybody changes.

Post reply on HN