Live data from Hacker News

Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

news.ycombinator.com

371–380 of 944 posts

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#371
post #290

Earlier quoted context omitted.

Then fire your shitty vendor or refund your customers. Nothing will change unless everybody changes.

You can't fire your SoC vendor especially once the product ships. And their are all PITA about security updates.

If you buy from a supplier with a contract that stipulates security updates then you certainly would define the damages which failure to fix will cause you, wouldn't you?

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#372

Earlier quoted context omitted.

I like this approach, it doesn't necessarily need to be just the "market" performing the audits however. The FDA handles audits of medical software companies just fine. Focusing on the Quality Management System and their Risk Assessment/Security practices seems like a solid approach, and of course centralize this data and make it easily searchable as much as possible, and provide API access to it in case vendors like…

FDA: $450K per product. And they aren't doing very much more than asking the vendor to describe their protocols, then ensure the vendor complies with their protocols and any agency guidance. Source: I work at an FDA-regulated company.

Did not know it was $450k per product, my second responsibility outside of software engineering was being the risk manager at my previous company as well which is FDA-regulated.

Still, many IoT companies that sell products don't even have protocols or a QMS at all, and need some kind of heat applied to them.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#373

Earlier quoted context omitted.

Thanks! I am thrilled that so many people are participating. The FCC is going to need a lot of this community's input over the next few years as more and more devices go online.

The biggest problem isn't even new regulations. The liability for violation always tends to be a rounding error to profits. Then, even if there are teeth, there is no money for enforcement which makes it all pointless. Look at how the FTC and SEC have completely failed us in the 21st century. Better regulations would matter if we ever bothered to enforce the ones we already have.

It's better to get the policies in place now and then complain about the lack of funding/enforcement. The mere threat of enforcement will cause some companies to design their products better and when a major security incident happens because of a bunch of insecure IoT devices and people are outraged it'll be a lot easier to motivate action if we can say "We already have rules that would have prevented this entirely, but the FCC wasn't provided the resources to enforce them."

That's a clear call to specific action as opposed to "We don't have rules that would have prevented this, and also many of the rules we do have across several agencies don't have enough funding to enforce rules designed to solve other problems."

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#374

Hi thanks for the work here. I read through (some) of the linked materials including the statements. The proposal itself is enormous, and all of it is extremely well researched. (Reading the comments here it reads like few folks read your links as most of the comments are addressed in some way). That that end, and I realize part of these exercises is exhaustiveness, due to the legal and regulatory nature, it would be…

Really appreciate your kind words and the effort required in getting your arms around so much material so quickly.

it would be really useful if there were a TLDR version

I agree; I'm hoping that the tech press takes up this topic, but an "official" one would make engagement much faster.

I think the labeling should be simple - like a small discrete set of classes for compliance that can be extended over time with further rules. So 20 years security updates is “platinum” 10 years is “gold” 5 is “silver” or something. Then the classes of label can accrete meaning over time as you enhance your proposals.

This is how I'm thinking about it too -- not just for support term, but for all kinds of things, FOSS firmware in escrow, bankruptcy transition plan, responsibility to publish and implement fixes from public databases -- there's so much that might go into each tier, and while I have my own ideas, it would be great to see the tech community take up these questions.

in some ways a way to work best is right here in the HN comments and then lifting material up into your direct work via the proposal and statement

Also true, and my team will be doing a detailed after-action on this thread once it winds down.

To that end maybe reaching out earlier in the process to get feedback would work

That's one to grow on for next time. The good news is that the final rule (I'd expect end of Q2 2024) will also be subject to notice-and-comment.

Seriously, a huge thank you for your close engagement. I'm really excited about what the tech world can bring to this high-level proposal.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#375
post #319
post #5

How about requiring devices to accept alternate, Free Software firmware, from the upstream provider? At the very least, it should be possible after some time period of no updates or insecurity, but a blanket requirement is less susceptible to games. Probably the best thing to happen to wireless routers is OpenWRT and the other descendents of the WRT firmware.

Possibly weird idea: federal firmware escrow. The OEM gets to put a stamp on their product after submitting firmware source/keys to the FCC. When the OEM either declares the product not supported or provides no updates for X length of time, the files are automatically published to a public repository. Perhaps there is an appropriate license which says essentially that it is almost public domain, with an exception (or…

So this feels like an amazing idea...but do we really want to give the federal government the keys to update your equipment remotely and to be able to pinpoint weaknesses of the source? This feels like Edward Snowden's grimmest nightmare.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#376

Earlier quoted context omitted.

I would think that tort law already achieves this - unless some law was passed that shields manufacturers from lawsuits. If that's the case, then the easy fix is removal of such shields instead of trying to create new regulations. Same applies to nearly all aspects of product liability.

I would expect some sort of license "agreement" that shields the manufacturer and resellers from all liability.

Not too many industries have such a shield. The nuclear industry comes to mind as an example of one that does.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#377
post #319

Earlier quoted context omitted.

Possibly weird idea: federal firmware escrow. The OEM gets to put a stamp on their product after submitting firmware source/keys to the FCC. When the OEM either declares the product not supported or provides no updates for X length of time, the files are automatically published to a public repository. Perhaps there is an appropriate license which says essentially that it is almost public domain, with an exception (or…

This is an amazing idea and I would only buy a product that has this stamp on them. I would put some additional triggers into the publication of source code as well, notably if the company goes out of business. I would also put some kind of timer and renewal process on it, like a company needs to recertify every 1-5 years (pros and cons to different time lengths) and that they have indeed been providing actual update…

The OEM could be allowed to choose their recertification period, perhaps with slight differences in requirements. Perhaps even different options offered by company size. For example 1-5 employee companies might get a "no recertification, provided as-is" option which releases automatically 3 years after filing. Vendors who re-certify every 6 months could get an extra mark on their stamp or whatever. There are tons of possibilities honestly, and though I've been thinking about it for a long time writing it is much easier to come up with more.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#378
As a firmware engineer, I'm one of the people who actually writes the code that goes inside the IoT devices. I'm very interested in what the FCC might be able to do here.

How does the FCC define a security flaw? Would updates only be distributed when there is a flaw that needs fixing?

Remote update mechanisms can themselves present security problems in some domains. Thus, some devices should only be updatable if the owner has physical access to the device. Will the manufacturer be liable for damages caused by attacks on vulnerable devices that were not sufficiently updated by their owners?

IoT is making its way into defense and enterprise environments where reliability is a matter of national security. An update nearly always results in some downtime for the device, even if it's just a couple seconds. Sometimes, it may be in the best interest of a device's owner to defer an update indefinitely, until that device's continuous operation is no longer mission-critical. Even if the owner can't control exactly what is in an update, they absolutely MUST be able to control when an update occurs.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#379

With all due respect, I think the market should address this. Like UL Approval from Underwriters Laboratories, players in the market can submit their products to an organization that vets their security and sets standards about updates, product lifetimes, security incident response time commitments etc to obtain their seal of approval. Perhaps the seal has grade levels to indicate the vendor's commitment to security.…

The UL example is one where it would be hard for improved security to happen by itself. UL was founded to solve for fire risk when insuring buildings. It received funding from underwriters that would benefit from the label. I don't see any particular entity benefiting from security labels - it's a problem of the "commons" where you generally need government intervention of some sort of.

I think the way to make this proposal work is to pass legislation to actually have meaningful financial liability for data breaches.

IFF companies have financial liability, then the market can be expected to find a cost-effective solution.

Without any selection pressure though, there is no reason tho think the market will spend resources to solve this. Users empirically don’t understand security, don’t price it appropriately in advance, and aren’t able to evaluate the security qualities even if they do want to pay more for a “secure” product.

Re: Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates

#380

Earlier quoted context omitted.

The UL example is one where it would be hard for improved security to happen by itself. UL was founded to solve for fire risk when insuring buildings. It received funding from underwriters that would benefit from the label. I don't see any particular entity benefiting from security labels - it's a problem of the "commons" where you generally need government intervention of some sort of.

You can't see the consumer benefitting from a certification label? Interesting. Also, the vendor benefits by gaining more sales.

I'm not sure you are following them. The UL was funded by the Insurance companies. Their point was that there was some organized, rich entity to pay for the costs of operation as they had a financial stake.
Post reply on HN